CVE-2020-19889

Publication date

2020-08-24 14:40:18

Family

mitre

State

PUBLISHED

Description

DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for index.php?dbhcms_pid=-70 can add a user.