CVE-2020-20595

MEDIUM WAF: Low
CVSS 6.5 Published: 2021-12-22
CWE-352

A cross-site request forgery (CSRF) in OPMS v1.3 and below allows attackers to arbitrarily add a user account via /user/add.

WAF Coverage Analysis

Cross-Site Request Forgery (CSRF) Low WAF Coverage

OWASP: A01:2021 Broken Access Control

Affected Software

VendorProductVersion
opms_projectopms1.3

References

Back to CVE Database