cve/2020/CVE-2020-26802.md
2024-05-25 21:48:12 +02:00

687 B

CVE-2020-26802

Description

forma.lms 2.3.0.2 is affected by Cross Site Request Forgery (CSRF) in formalms/appCore/index.php?r=lms/profile/show&ap=saveinfo via a GET request to change the admin email address in order to accomplish an account takeover.

POC

Reference

Github

No PoCs found on GitHub currently.