CVE-2020-18648

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
22/06/2021
Last modified:
05/10/2022

Description

Cross Site Request Forgery (CSRF) in JuQingCMS v1.0 allows remote attackers to gain local privileges via the component "JuQingCMS_v1.0/admin/index.php?c=administrator&a=add".

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:juqingcms:juqingcms:1.0:*:*:*:*:*:*:*