← Back to CVEs
CVE-2020-23960
HIGH8.8
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in the Admin Console in Fork before 5.8.3 allows remote attackers to perform unauthorized actions as administrator to (1) approve the mass of the user's comments, (2) restoring a deleted user, (3) installing or running modules, (4) resetting the analytics, (5) pinging the mailmotor api, (6) uploading things to the media library, (7) exporting locale.
CVE Details
CVSS v3.1 Score8.8
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionREQUIRED
Published1/11/2021
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0
Affected Products
fork-cms:fork_cms
Weaknesses (CWE)
CWE-352
References
https://github.com/forkcms/forkcms/pull/3123(cve@mitre.org)
https://www.fork-cms.com/blog/detail/fork-5.8.3-released(cve@mitre.org)
https://github.com/forkcms/forkcms/pull/3123(af854a3a-2127-422b-91ae-364da2661108)
https://www.fork-cms.com/blog/detail/fork-5.8.3-released(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.