CVE-2020-24739: Idreamsoft Icms

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A CSRF vulnerability was found in iCMS v7.0.0 in the background deletion administrator account. When missing the CSRF_TOKEN and can still request normally, all administrators except the initial administrator will be deleted.

Affected products

Published 2020-09-10. Last modified 2026-06-17.