Home

Description

Snews CMS 1.7 contains a cross-site request forgery vulnerability that allows attackers to change administrator credentials without authentication by crafting malicious HTML forms. Attackers can trick authenticated administrators into visiting a page containing a hidden form that submits POST requests to the changeup action, modifying the admin username and password parameters to gain unauthorized access.

PUBLISHED Reserved 2026-04-04 | Published 2026-04-04 | Updated 2026-04-06 | Assigner VulnCheck




MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L
MEDIUM: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Problem types

Cross-Site Request Forgery (CSRF)

Product status

1.7
affected

Credits

Ashiyane Digital Security Team finder

References

www.exploit-db.com/exploits/40705 (ExploitDB-40705) exploit

www.vulncheck.com/...cross-site-request-forgery-via-changeup (VulnCheck Advisory: Snews CMS 1.7 Cross-Site Request Forgery via changeup) third-party-advisory

cve.org (CVE-2016-20051)

nvd.nist.gov (CVE-2016-20051)

Download JSON