CVE-2020-24130

Source
https://cve.org/CVERecord?id=CVE-2020-24130
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-24130.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-24130
Published
2021-08-20T20:15:06Z
Modified
2026-07-09T00:37:07Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H CVSS Calculator
Summary
[none]
Details

A cross site request forgery (CSRF) vulnerability in the configure.html component of Ponzu 0.11.0 allows attackers to change user and administrator credentials, and add or delete administrator accounts.

References

Affected packages

Git / github.com/ponzu-cms/ponzu

Affected ranges

Type
GIT
Repo
https://github.com/ponzu-cms/ponzu
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:ponzu-cms:ponzu:0.11.0:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0.11.0"
        },
        {
            "last_affected": "0.11.0"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

0.*
0.11.0
v0.*
v0.11.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-24130.json"