VULNERABILITY INTELLIGENCE

CVE-2016-20051

CVSS score6.9 MEDIUM
EPSS probability0.16%
CISA KEVNot currently listed
Published2026-04-04
Last modified2026-07-21
CVSS vectorCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L

Description

Snews CMS 1.7 contains a cross-site request forgery vulnerability that allows attackers to change administrator credentials without authentication by crafting malicious HTML forms. Attackers can trick authenticated administrators into visiting a page containing a hidden form that submits POST requests to the changeup action, modifying the admin username and password parameters to gain unauthorized access.

Weakness classification

  • CWE-352: Cross-Site Request Forgery (CSRF)

Primary references