Medium severity5.3NVD Advisory· Published Apr 4, 2026· Updated Apr 14, 2026
CVE-2016-20051
CVE-2016-20051
Description
Snews CMS 1.7 contains a cross-site request forgery vulnerability that allows attackers to change administrator credentials without authentication by crafting malicious HTML forms. Attackers can trick authenticated administrators into visiting a page containing a hidden form that submits POST requests to the changeup action, modifying the admin username and password parameters to gain unauthorized access.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.exploit-db.com/exploits/40705nvdExploitThird Party AdvisoryVDB Entry
- www.vulncheck.com/advisories/snews-cms-cross-site-request-forgery-via-changeupnvdThird Party Advisory
News mentions
0No linked articles in our index yet.