Files
CVEs-PoC/2020/CVE-2020-36140.md
T
2024-05-25 21:48:12 +02:00

18 lines
684 B
Markdown

### [CVE-2020-36140](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-36140)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
BloofoxCMS 0.5.2.1 allows Cross-Site Request Forgery (CSRF) via 'mode=settings&page=editor', as demonstrated by use of 'mode=settings&page=editor' to change any file content (Locally/Remotely).
### POC
#### Reference
- https://muteb.io/2020/12/29/BloofoxCMS-Multiple-Vulnerabilities.html
#### Github
No PoCs found on GitHub currently.