CVE-2020-10540: Untis Webuntis

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Untis WebUntis before 2020.9.6 allows CSRF for certain combinations of rights and modules.

Affected products

  • Untis Webuntis: before 2020.9.6 (fixed in 2020.9.6)

Published 2020-03-13. Last modified 2026-06-17.