Junglewise Threat Intelligence

CVE-2019-25682: VictorAlagwu CMSsite CSRF in users.php

CVE-2019-25682 · Severity: medium · CVSS 4.3 · Published 2026-04-05

Technologies: Victoralagwu Cmssite. Vendors: Victoralagwu.

Executive brief

CMSsite is a content management system used to build and manage websites. A security flaw allows an attacker to trick a logged-in administrator into unknowingly performing actions like creating, modifying, or deleting user accounts. This could lead to an unauthorized takeover of the website's management functions if an administrator visits a malicious link while logged in.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in CMSsite 1.0 due to a lack of anti-CSRF tokens in administrative forms. The vulnerability is located in the 'admin/users.php' endpoint. An unauthenticated remote attacker can craft a malicious HTML page or form that, when visited by an authenticated administrator, triggers a POST request to perform actions such as adding a new user (source=add_user), editing existing users (source=edit_user), or deleting accounts (del=1). This can result in unauthorized administrative account creation or modification. The software is currently archived on GitHub and no official patch has been released.

Affected products

  • VictorAlagwu CMSsite 1.0

Timeline

  • 2019-03-01: disclosed: Vulnerability discovered by Mr Winst0n
  • 2019-03-04: other: Exploit published on Exploit-DB
  • 2022-03-06: other: GitHub repository archived by owner
  • 2026-04-05: advisory: CVE published and NVD entry created

References

Related threats