No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 18 May 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 16 May 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | bloofoxCMS 0.5.2.1 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in users into visiting malicious pages. Attackers can craft hidden forms targeting the admin user creation endpoint to add new administrative accounts with arbitrary credentials without requiring explicit user consent. | |
| Title | bloofoxCMS 0.5.2.1 Cross-Site Request Forgery via user add | |
| First Time appeared |
Bloofox
Bloofox bloofoxcms |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:bloofox:bloofoxcms:0.1.0:*:*:*:*:*:*:* cpe:2.3:a:bloofox:bloofoxcms:0.1.1:*:*:*:*:*:*:* cpe:2.3:a:bloofox:bloofoxcms:0.1.2:*:*:*:*:*:*:* cpe:2.3:a:bloofox:bloofoxcms:0.1.3:*:*:*:*:*:*:* cpe:2.3:a:bloofox:bloofoxcms:0.2.0:*:*:*:*:*:*:* cpe:2.3:a:bloofox:bloofoxcms:0.2.1:*:*:*:*:*:*:* cpe:2.3:a:bloofox:bloofoxcms:0.2.2:*:*:*:*:*:*:* cpe:2.3:a:bloofox:bloofoxcms:0.2.3.1:*:*:*:*:*:*:* cpe:2.3:a:bloofox:bloofoxcms:0.2.3:*:*:*:*:*:*:* cpe:2.3:a:bloofox:bloofoxcms:0.3.0:*:*:*:*:*:*:* cpe:2.3:a:bloofox:bloofoxcms:0.3.1:*:*:*:*:*:*:* cpe:2.3:a:bloofox:bloofoxcms:0.3.2:*:*:*:*:*:*:* cpe:2.3:a:bloofox:bloofoxcms:0.3.3:*:*:*:*:*:*:* cpe:2.3:a:bloofox:bloofoxcms:0.3.4:*:*:*:*:*:*:* cpe:2.3:a:bloofox:bloofoxcms:0.3.5:*:*:*:*:*:*:* cpe:2.3:a:bloofox:bloofoxcms:0.4.0:*:*:*:*:*:*:* cpe:2.3:a:bloofox:bloofoxcms:0.4.1:*:*:*:*:*:*:* cpe:2.3:a:bloofox:bloofoxcms:0.5.0:*:*:*:*:*:*:* cpe:2.3:a:bloofox:bloofoxcms:0.5.1:*:*:*:*:*:*:* cpe:2.3:a:bloofox:bloofoxcms:0.5.2.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Bloofox
Bloofox bloofoxcms |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-18T12:38:58.585Z
Reserved: 2026-05-15T14:57:57.144Z
Link: CVE-2020-37241
Updated: 2026-05-18T12:38:55.354Z
Status : Deferred
Published: 2026-05-16T16:16:20.350
Modified: 2026-05-18T17:26:40.167
Link: CVE-2020-37241
No data.
OpenCVE Enrichment
Updated: 2026-05-16T18:30:28Z