CVE-2020-19047: Iwebshop

High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Cross Site Request Forgey (CSRF) in iWebShop v5.3 allows remote atatckers to execute arbitrary code via malicious POST request to the component '/index.php?controller=system&action=admin_edit_act'.

Affected products

Published 2021-08-31. Last modified 2026-06-17.