CVE-2020-35347

MEDIUM WAF: Low
CVSS 6.5 Published: 2020-12-26
CWE-352

CXUUCMS V3 3.1 has a CSRF vulnerability that can add an administrator account via admin.php?c=adminuser&a=add.

WAF Coverage Analysis

Cross-Site Request Forgery (CSRF) Low WAF Coverage

OWASP: A01:2021 Broken Access Control

Affected Software

VendorProductVersion
cxuucxuucms3.1

References

Back to CVE Database