A cross-site request forgery (CSRF) in Rockoa v1.9.8 allows an authenticated attacker to arbitrarily add an administrator account.
References
Link Resource
http://www.rockoa.com/view_demo.html Broken Link Product
https://github.com/alixiaowei/alixiaowei.github.io/issues/1 Exploit Issue Tracking Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-12-22T22:35:20

Updated: 2021-12-22T22:35:20

Reserved: 2020-08-13T00:00:00


Link: CVE-2020-20593

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-12-22T23:15:07.537

Modified: 2021-12-28T19:55:33.713


Link: CVE-2020-20593

JSON object: View

cve-icon Redhat Information

No data.

CWE