CVE-2020-24739: Idreamsoft Icms
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
A CSRF vulnerability was found in iCMS v7.0.0 in the background deletion administrator account. When missing the CSRF_TOKEN and can still request normally, all administrators except the initial administrator will be deleted.
Affected products
- Idreamsoft Icms: version 7.0.0 only
Published 2020-09-10. Last modified 2026-06-17.