CVE-2020-18264: Simple-Log Project Simple-Log
High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.
Cross Site Request Forgery (CSRF) in Simple-Log v1.6 allows remote attackers to gain privilege and execute arbitrary code via the component "Simple-Log/admin/admin.php?act=act_edit_member".
Affected products
- Simple-Log Project Simple-Log: version 1.6 only
Published 2021-06-07. Last modified 2026-06-17.