A cross site request forgery (CSRF) vulnerability in the /xyhai.php?s=/Auth/editUser URI of XYHCMS V3.6 allows attackers to edit any information of the administrator such as the name, e-mail, and password.
                
            References
                    | Link | Resource | 
|---|---|
| http://www.xyhcms.com/Show/download/id/2/at/0.html | Broken Link | 
| http://xyhcms.com | Vendor Advisory | 
| https://github.com/0xyu/PHP_Learning/issues/4 | Exploit Third Party Advisory | 
Configurations
                    History
                    No history.
Information
                Published : 2021-07-08 16:15
Updated : 2021-07-12 12:56
NVD link : CVE-2020-20586
Mitre link : CVE-2020-20586
CVE.ORG link : CVE-2020-20586
JSON object : View
Products Affected
                xyhcms
- xyhcms
 
CWE
                
                    
                        
                        CWE-352
                        
            Cross-Site Request Forgery (CSRF)
