CVE-2020-21236

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
27/12/2021
Last modified:
10/01/2022

Description

A vulnerability in /damicms-master/admin.php?s=/Article/doedit of DamiCMS v6.0 allows attackers to compromise and impersonate user accounts via obtaining a user's session cookie.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:damicms:damicms:6.0.0:*:*:*:*:*:*:*