PT-2026-30349 · Snewscms · Snews

CVE-2016-20051

·

Published

2026-04-04

·

Updated

2026-07-21

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Snews CMS version 1.7
Description Cross-site request forgery occurs when an attacker tricks an authenticated user into performing an action they did not intend to. This issue allows attackers to change administrator credentials without authentication by crafting malicious HTML forms. By deceiving authenticated administrators into visiting a page with a hidden form, attackers can send POST requests to the changeup action to modify the username and password parameters and gain unauthorized access.
Recommendations As a temporary workaround, restrict access to the changeup action to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-20051

Affected Products

Snews