Cross-Site Request Forgery in EasyCMS by Yohoho221
CVE-2020-24271
8.8HIGH
What is CVE-2020-24271?
A Cross-Site Request Forgery (CSRF) vulnerability exists in EasyCMS version 1.6, enabling an attacker to create an admin account without authorization. By exploiting this flaw, an attacker can craft a malicious request targeting the index.php endpoint to insert a new user with administrative privileges. This poses a significant security risk, as it allows unauthorized users to gain control over the EasyCMS application, potentially compromising sensitive data and overall system integrity.
