CVE-2019-9688: Sftnow

High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.

sftnow through 2018-12-29 allows index.php?g=Admin&m=User&a=add_post CSRF to add an admin account.

Affected products

  • Sftnow Sftnow: up to and including 2018-12-29

Published 2019-03-11. Last modified 2026-06-17.