CVE-2019-25682 PUBLISHED

CMSsite 1.0 Cross-Site Request Forgery via users.php

Assigner: VulnCheck
Reserved: 05.04.2026 Published: 05.04.2026 Updated: 06.04.2026

CMSsite 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious HTML forms. Attackers can trick authenticated administrators into visiting crafted pages that submit POST requests to the users.php endpoint with parameters like source=add_user, source=edit_user, or del=1 to create, modify, or delete admin accounts.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L
CVSS Score: 5.3

Product Status

Vendor VictorAlagwu
Product CMSsite
Versions
  • Version 1.0 is affected

Credits

  • Mr Winst0n finder

References

Problem Types

  • Cross-Site Request Forgery (CSRF) CWE