CVE-2016-20054
EUVD-2016-1087304.04.2026, 20:16
Nodcms contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious forms. Attackers can trick authenticated administrators into submitting requests to admin/user_manipulate and admin/settings/generall endpoints to create users or modify application settings without explicit consent.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| nodcms | nodcms | 1.0 |
𝑥
= Vulnerable software versions