Record summary

CVE-2020-26802 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.

Description

forma.lms 2.3.0.2 is affected by Cross Site Request Forgery (CSRF) in formalms/appCore/index.php?r=lms/profile/show&ap=saveinfo via a GET request to change the admin email address in order to accomplish an account takeover.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBforma.lms 5.6.40 - Cross-Site Request Forgery (Change Admin Email)ExploitDB exploitby Daniel OrtizNot analyzed1 file
ExploitDB

PoC details

References

2