CVE-2020-37091 PUBLISHED

Maian Support Helpdesk 4.3 - Cross-Site Request Forgery (Add Admin)

Assigner: VulnCheck
Reserved: 01.02.2026 Published: 03.02.2026 Updated: 04.02.2026

Maian Support Helpdesk 4.3 contains a cross-site request forgery vulnerability that allows attackers to create administrative accounts without authentication. Attackers can craft malicious HTML forms to add admin users and upload PHP files with unrestricted file upload capabilities through the FAQ attachment system.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.1

Product Status

Vendor Maian Media
Product Maian Support Helpdesk
Versions
  • Version 4.3 is affected

Credits

  • Besim ALTINOK finder

References

Problem Types

  • Cross-Site Request Forgery (CSRF) CWE