Sistem Informasi Pengumuman Kelulusan Online 1.0 - Cross-Site Request Forgery
Vulnerability Description
Sistem Informasi Pengumuman Kelulusan Online 1.0 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized admin users through the tambahuser.php endpoint. Attackers can craft a malicious HTML form to submit admin credentials and create new administrative accounts without the victim's consent.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-37046
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Extinction
Affected Vendor
Adikiss
View all reports →