Security Advisory

CVE-2020-21139

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-11-04 19:09:11
Last updated 2024-08-04 14:22:25
Assigner mitre
State PUBLISHED

Description

EC Cloud E-Commerce System v1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add admin accounts via /admin.html?do=user&act=add.