VYPR

Sistem Informasi Pengumuman Kelulusan Online

by adikiss.net

CVEs (1)

  • CVE-2020-37046MedJan 30, 2026
    risk 0.34cvss 5.3epss 0.00

    Sistem Informasi Pengumuman Kelulusan Online 1.0 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized admin users through the tambahuser.php endpoint. Attackers can craft a malicious HTML form to submit admin credentials and create new administrative accounts without the victim's consent.