RSS   Vulnerabilities for 'Candidats'   RSS

2020-02-22
 
CVE-2020-9341

CWE-352
 

 
CandidATS 2.1.0 is vulnerable to CSRF that allows for an administrator account to be added via the index.php?m=settings&a=addUser URI.

 


Copyright 2020, cxsecurity.com

 

Back to Top