WTCMS 1.0 contains a cross-site request forgery (CSRF) vulnerability in the index.php?g=admin&m=nav&a=add_post component that allows attackers to arbitrarily add articles in the administrator background.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-20343
Reference (s):
- https://github.com/taosir/wtcms/issues/8

