CVE-2020-24130

Source
https://cve.org/CVERecord?id=CVE-2020-24130
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-24130.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2020-24130
Published
2021-08-20T20:15:06.947Z
Modified
2025-11-14T10:57:17.205927Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H CVSS Calculator
Summary
[none]
Details

A cross site request forgery (CSRF) vulnerability in the configure.html component of Ponzu 0.11.0 allows attackers to change user and administrator credentials, and add or delete administrator accounts.

References

Affected packages

Git / github.com/ponzu-cms/ponzu

Affected ranges

Type
GIT
Repo
https://github.com/ponzu-cms/ponzu
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

0.*
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
v0.*
v0.10.0
v0.10.1
v0.11.0

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-24130.json"