A cross-site request forgery (CSRF) vulnerability in the admin panel in SkySystem Arfa-CMS before 5.1.3132 allows remote attackers to add a new administrator, leading to escalation of privileges.
CWE-352 | Cross Site Request Forgery (CSRF)
SkySystem (https://skyss.ru/)
Arfa-CMS - 5.1.3124 and earlier
true
true
Kirill Kalimmulin