Snews CMS 1.7 contains a cross-site request forgery vulnerability that allows attackers to change administrator credentials without authentication by crafting malicious HTML forms. Attackers can trick authenticated administrators into visiting a page containing a hidden form that submits POST requests to the changeup action, modifying the admin username and password parameters to gain unauthorized access.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 04 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Snews CMS 1.7 contains a cross-site request forgery vulnerability that allows attackers to change administrator credentials without authentication by crafting malicious HTML forms. Attackers can trick authenticated administrators into visiting a page containing a hidden form that submits POST requests to the changeup action, modifying the admin username and password parameters to gain unauthorized access. | |
| Title | Snews CMS 1.7 Cross-Site Request Forgery via changeup | |
| First Time appeared |
Snewscms
Snewscms snews |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:snewscms:snews:1.7:*:*:*:*:*:*:* | |
| Vendors & Products |
Snewscms
Snewscms snews |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-04T19:59:42.176Z
Reserved: 2026-04-04T13:32:48.661Z
Link: CVE-2016-20051
No data.
Status : Received
Published: 2026-04-04T14:16:17.370
Modified: 2026-04-04T14:16:17.370
Link: CVE-2016-20051
No data.
OpenCVE Enrichment
No data.
Weaknesses