CVE-2016-20053 - CVE House
Back to Database
Status published Medium CVE-2016-20053

Redaxo CMS 5.2 Cross-Site Request Forgery via users endpoint

Vulnerability Description

Redaxo CMS 5.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create administrative user accounts by tricking authenticated administrators into visiting malicious pages. Attackers can craft HTML forms targeting the users endpoint with hidden fields containing admin credentials and account parameters to add new administrator accounts without user consent.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-20053

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Ashiyane Digital Security Team

Affected Vendor

Affected Software

Redaxo CMS
Vulnerable Versions:
5.2

Timeline

Official Publish: April 4th, 2026
Last Modified: April 6th, 2026
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Weaknesses (CWE)