Bloofox · Bloofoxcms · CVE-2020-37241
**Name of the Vulnerable Software and Affected Versions**
bloofoxCMS version 0.5.2.1
**Description**
A cross-site request forgery issue allows attackers to perform administrative actions by tricking authenticated users into visiting malicious pages. Attackers can use hidden forms targeting the admin user creation endpoint to create new administrative accounts with arbitrary credentials without the user's consent.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.