cve/2020/CVE-2020-19889.md
2024-06-09 00:33:16 +00:00

663 B

CVE-2020-19889

Description

DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for index.php?dbhcms_pid=-70 can add a user.

POC

Reference

Github