Security Advisory

CVE-2020-23837

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2020-09-25 03:53:35
Last updated 2024-08-04 15:05:11
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

A Cross-Site Request Forgery (CSRF) vulnerability in the Multi User plugin 1.8.2 for GetSimple CMS allows remote attackers to add admin (or other) users after an authenticated admin visits a third-party site or clicks on a URL.