VYPR
Medium severity4.5NVD Advisory· Published Jul 8, 2021· Updated Jul 9, 2026

CVE-2020-20586

CVE-2020-20586

Description

A cross site request forgery (CSRF) vulnerability in the /xyhai.php?s=/Auth/editUser URI of XYHCMS V3.6 allows attackers to edit any information of the administrator such as the name, e-mail, and password.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • XYHCMS/XYHCMS2 versions
    cpe:2.3:a:xyhcms:xyhcms:3.6:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:xyhcms:xyhcms:3.6:*:*:*:*:*:*:*
    • (no CPE)range: = 3.6
  • XYHCMS/XYHCMSdescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.