CVE-2020-10057: Metalgenix Genixcms
High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.
GeniXCMS 1.1.7 is vulnerable to user privilege escalation due to broken access control. This issue exists because of an incomplete fix for CVE-2015-2680, in which "token" is used as a CSRF protection mechanism, but without validation that "token" is associated with an administrative user.
Affected products
- Metalgenix Genixcms: version 1.1.7 only
Published 2020-03-04. Last modified 2026-06-17.