Junglewise Threat Intelligence

CVE-2016-20054: nodcms nodCMS CSRF in administrative endpoints

CVE-2016-20054 · Severity: medium · CVSS 4.3 · Published 2026-04-04

Vendors: Packagist.

Executive brief

Nodcms, a content management system, is vulnerable to an attack that can trick administrators into performing unintended actions. By convincing a logged-in administrator to visit a malicious webpage, an attacker can silently create new user accounts or change website settings. This could lead to unauthorized access to the management console or disruption of the website's configuration.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in nodCMS 1.0 due to a lack of anti-CSRF tokens on administrative endpoints. Specifically, the 'admin/user_manipulate' and 'admin/settings/generall' endpoints do not validate the origin of POST requests. An unauthenticated remote attacker can exploit this by crafting a malicious HTML page that, when visited by an authenticated administrator, automatically submits a form to the vulnerable application. Successful exploitation allows the attacker to create new administrative users or inject malicious scripts into application settings (XSS), leading to full site compromise.

Affected products

  • nodcms nodCMS 1.0

Timeline

  • 2016-10-29: disclosed: Vulnerability discovered by Ashiyane Digital Security Team
  • 2016-11-03: other: Exploit published on Exploit-DB
  • 2026-04-04: advisory: NVD publication date

References

Related threats