CVE-2020-19268: Dswjcms Project Dswjcms
Medium severity, CVSS 5.7. EPSS: 0.3% chance of exploitation in the next 30 days.
A cross-site request forgery (CSRF) in index.php/Dswjcms/User/tfAdd of Dswjcms 1.6.4 allows authenticated attackers to arbitrarily add administrator users.
Affected products
- Dswjcms Project Dswjcms: version 1.6.4 only
Published 2021-09-09. Last modified 2026-06-17.