Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 06 Apr 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 05 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CMSsite 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious HTML forms. Attackers can trick authenticated administrators into visiting crafted pages that submit POST requests to the users.php endpoint with parameters like source=add_user, source=edit_user, or del=1 to create, modify, or delete admin accounts. | |
| Title | CMSsite 1.0 Cross-Site Request Forgery via users.php | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-06T15:27:11.308Z
Reserved: 2026-04-05T15:16:06.447Z
Link: CVE-2019-25682
Updated: 2026-04-06T15:08:15.899Z
Status : Received
Published: 2026-04-05T21:16:46.630
Modified: 2026-04-05T21:16:46.630
Link: CVE-2019-25682
No data.
OpenCVE Enrichment
No data.