CVE-2016-20051 PUBLISHED

Snews CMS 1.7 Cross-Site Request Forgery via changeup

Assigner: VulnCheck
Reserved: 04.04.2026 Published: 04.04.2026 Updated: 04.04.2026

Snews CMS 1.7 contains a cross-site request forgery vulnerability that allows attackers to change administrator credentials without authentication by crafting malicious HTML forms. Attackers can trick authenticated administrators into visiting a page containing a hidden form that submits POST requests to the changeup action, modifying the admin username and password parameters to gain unauthorized access.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L
CVSS Score: 6.9

Product Status

Vendor Snewscms
Product Snews CMS Cross Site Request Forgery
Versions
  • Version 1.7 is affected

Credits

  • Ashiyane Digital Security Team finder

References

Problem Types

  • Cross-Site Request Forgery (CSRF) CWE