LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2013-20005

Published
CVSS5.3
Severitymedium
WeaknessCWE-79
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Description

Qool CMS 2.0 RC2 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in users into visiting malicious web pages. Attackers can forge POST requests to the /admin/adduser endpoint with parameters like username, password, email, and level to create root-level user accounts without user consent.

References

← Back to the CVE Tracker

Our coverage of CVE-2013-20005

No stories yet. This page updates automatically when we publish reporting that references CVE-2013-20005.