CVE-2020-14025

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
22/09/2020
Last modified:
26/09/2020

Description

Ozeki NG SMS Gateway through 4.17.6 has multiple CSRF vulnerabilities. For example, an administrator, by following a link, can be tricked into making unwanted changes such as installing new modules or changing a password.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ozeki:ozeki_ng_sms_gateway:*:*:*:*:*:*:*:* 4.17.6 (including)