Medium severity5.3NVD Advisory· Published Apr 4, 2026· Updated Apr 14, 2026
CVE-2016-20051
CVE-2016-20051
Description
Snews CMS 1.7 contains a cross-site request forgery vulnerability that allows attackers to change administrator credentials without authentication by crafting malicious HTML forms. Attackers can trick authenticated administrators into visiting a page containing a hidden form that submits POST requests to the changeup action, modifying the admin username and password parameters to gain unauthorized access.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
2- www.exploit-db.com/exploits/40705nvdExploitThird Party AdvisoryVDB Entry
- www.vulncheck.com/advisories/snews-cms-cross-site-request-forgery-via-changeupnvdThird Party Advisory
News mentions
0No linked articles in our index yet.