CVE-2020-24130: Ponzu-CMS Ponzu
High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.
A cross site request forgery (CSRF) vulnerability in the configure.html component of Ponzu 0.11.0 allows attackers to change user and administrator credentials, and add or delete administrator accounts.
Affected products
- Ponzu-CMS Ponzu: version 0.11.0 only
Published 2021-08-20. Last modified 2026-06-17.