A Cross-Site Request Forgery (CSRF) in the component admin.php/admin/type/info.html of Maccms 10 allows attackers to gain administrator privileges.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-21386
Reference (s):
- https://github.com/magicblack/maccms10/issues/126