CVE-2019-18220: Sitemagic
High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.
Sitemagic CMS 4.4.1 is affected by a Cross-Site-Request-Forgery (CSRF) issue as it doesn't implement any method to validate incoming requests, allowing the execution of critical functionalities via spoofed requests. This behavior could be abused by a remote unauthenticated attacker to trick Sitemagic users into performing unwarranted actions.
Affected products
- Sitemagic Sitemagic: version 4.4.1 only
Published 2019-10-23. Last modified 2026-06-17.