CVE-2020-37054
MEDIUMNavigate CMS 2.8.7 - Cross-Site Request Forgery via Extension Upload
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-37054. PoCs published by Gus Ralph.
AI-analyzed exploit summary This exploit demonstrates a Cross-Site Request Forgery (CSRF) vulnerability in Navigate CMS 2.8.7, allowing an attacker to add an admin user by tricking an authenticated admin into accessing a malicious HTML page. The exploit constructs a multipart/form-data request to upload a malicious plugin ZIP file.
Description
Navigate CMS 2.8.7 contains a cross-site request forgery vulnerability that allows attackers to upload malicious extensions through a crafted HTML page. Attackers can trick authenticated administrators into executing arbitrary file uploads by leveraging the extension upload functionality without additional validation.
Exploits (1)
This exploit demonstrates a Cross-Site Request Forgery (CSRF) vulnerability in Navigate CMS 2.8.7, allowing an attacker to add an admin user by tricking an authenticated admin into accessing a malicious HTML page. The exploit constructs a multipart/form-data request to upload a malicious plugin ZIP file.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N