CVE-2020-24130: Ponzu-CMS Ponzu

High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.

A cross site request forgery (CSRF) vulnerability in the configure.html component of Ponzu 0.11.0 allows attackers to change user and administrator credentials, and add or delete administrator accounts.

Affected products

Published 2021-08-20. Last modified 2026-06-17.