A Cross Site Request Forgery (CSRF) vulnerability was discovered in PHPMyWind 5.6 which allows attackers to create a new administrator account without authentication.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-19964
Reference (s):
- http://phpmywind.com
- https://github.com/gaozhifeng/PHPMyWind
- https://github.com/gaozhifeng/PHPMyWind/issues/9

