CVE-2019-20077

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
05/01/2020
Last modified:
09/01/2020

Description

The Typesetter CMS 5.1 logout functionality is affected by a CSRF vulnerability. The logout function of the admin panel is not protected by any CSRF tokens. An attacker can logout the user using this vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:typesettercms:typesetter:5.1:*:*:*:*:*:*:*