Nodcms contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious forms. Attackers can trick authenticated administrators into submitting requests to admin/user_manipulate and admin/settings/generall endpoints to create users or modify application settings without explicit consent.
Metrics
Affected Vendors & Products
References
History
Sat, 04 Apr 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nodcms contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious forms. Attackers can trick authenticated administrators into submitting requests to admin/user_manipulate and admin/settings/generall endpoints to create users or modify application settings without explicit consent. | |
| Title | Nodcms Cross Site Request Forgery via admin endpoints | |
| First Time appeared |
Nodcms
Nodcms nodcms |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:nodcms:nodcms:1.0:*:*:*:*:*:*:* cpe:2.3:a:nodcms:nodcms:2.0:*:*:*:*:*:*:* cpe:2.3:a:nodcms:nodcms:3.0:*:*:*:*:*:*:* cpe:2.3:a:nodcms:nodcms:3.1:*:*:*:*:*:*:* cpe:2.3:a:nodcms:nodcms:3.2.0:*:*:*:*:*:*:* cpe:2.3:a:nodcms:nodcms:3.2.1.2:*:*:*:*:*:*:* cpe:2.3:a:nodcms:nodcms:3.2.1.3:*:*:*:*:*:*:* cpe:2.3:a:nodcms:nodcms:3.2.1.4:*:*:*:*:*:*:* cpe:2.3:a:nodcms:nodcms:3.2.1.5:*:*:*:*:*:*:* cpe:2.3:a:nodcms:nodcms:3.2.1:*:*:*:*:*:*:* cpe:2.3:a:nodcms:nodcms:3.2.2:*:*:*:*:*:*:* cpe:2.3:a:nodcms:nodcms:3.3.0:*:*:*:*:*:*:* cpe:2.3:a:nodcms:nodcms:3.3.1:*:*:*:*:*:*:* cpe:2.3:a:nodcms:nodcms:3.4.0:*:*:*:*:*:*:* cpe:2.3:a:nodcms:nodcms:3.4.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Nodcms
Nodcms nodcms |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-04T19:59:44.200Z
Reserved: 2026-04-04T13:34:39.170Z
Link: CVE-2016-20054
No data.
Status : Received
Published: 2026-04-04T20:16:15.940
Modified: 2026-04-04T20:16:15.940
Link: CVE-2016-20054
No data.