CVE-2020-37241

MEDIUM

bloofoxCMS 0.5.2.1 Cross-Site Request Forgery via user add

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-37241. PoCs published by LiPeiYi.

AI-analyzed exploit summary This is a functional CSRF exploit for bloofoxCMS 0.5.2.1 that adds an admin user via a crafted HTML form submission. The PoC demonstrates the vulnerability by automating the submission of user creation parameters without requiring user interaction beyond visiting the malicious page.

Description

bloofoxCMS 0.5.2.1 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in users into visiting malicious pages. Attackers can craft hidden forms targeting the admin user creation endpoint to add new administrative accounts with arbitrary credentials without requiring explicit user consent.

Exploits (1)

exploitdb WORKING POC
by LiPeiYi · htmlwebappsphp
https://www.exploit-db.com/exploits/49507

This is a functional CSRF exploit for bloofoxCMS 0.5.2.1 that adds an admin user via a crafted HTML form submission. The PoC demonstrates the vulnerability by automating the submission of user creation parameters without requiring user interaction beyond visiting the malicious page.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: bloofoxCMS 0.5.1.0 to 0.5.2.1
No auth needed
Prerequisites: Victim must be logged into the admin panel · Attacker must lure victim to a page hosting the exploit
devstral-2 · analyzed May 16, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit exploit
ExploitDB-49507
https://www.exploit-db.com/exploits/49507
Product product
Official Product Homepage
https://www.bloofox.com/
Third Party Advisory third-party-advisory
VulnCheck Advisory: bloofoxCMS 0.5.2.1 Cross-Site Request Forgery via user add
https://www.vulncheck.com/advisories/bloofoxcms-cross-site-request-forgery-via-user-add

Scores

CVSS v3 5.3
EPSS 0.0002
EPSS Percentile 5.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-352
Status published
Products (1)
Bloofox/bloofoxCMS 0.5.1.0 - 0.5.2.1
Published May 16, 2026
Tracked Since May 16, 2026