CVE-2020-19268: Dswjcms Project Dswjcms

Medium severity, CVSS 5.7. EPSS: 0.3% chance of exploitation in the next 30 days.

A cross-site request forgery (CSRF) in index.php/Dswjcms/User/tfAdd of Dswjcms 1.6.4 allows authenticated attackers to arbitrarily add administrator users.

Affected products

Published 2021-09-09. Last modified 2026-06-17.