2024-05-25 21:48:12 +02:00
|
|
|
### [CVE-2020-19889](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-19889)
|
|
|
|

|
|
|
|

|
|
|
|

|
|
|
|
|
|
|
|
### Description
|
|
|
|
|
|
|
|
DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for index.php?dbhcms_pid=-70 can add a user.
|
|
|
|
|
|
|
|
### POC
|
|
|
|
|
|
|
|
#### Reference
|
|
|
|
- https://github.com/fragrant10/cve/tree/master/dbhcms1.2.0#11
|
2024-06-09 00:33:16 +00:00
|
|
|
- https://github.com/fragrant10/cve/tree/master/dbhcms1.2.0#11
|
2024-05-25 21:48:12 +02:00
|
|
|
|
|
|
|
#### Github
|
|
|
|
- https://github.com/fragrant10/cve
|
|
|
|
|