Junglewise Threat Intelligence

CVE-2020-37241: bloofoxCMS CSRF in administrative user creation

CVE-2020-37241 · Severity: medium · CVSS 5.3 · Published 2026-05-16

Executive brief

bloofoxCMS, an open-source content management system, is vulnerable to an attack that could allow unauthorized individuals to gain administrative control. By tricking a logged-in administrator into visiting a malicious website, an attacker can silently create a new administrative account with their own credentials. This could lead to a full takeover of the website, allowing the attacker to modify content or access sensitive data.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in bloofoxCMS versions 0.5.1.0 through 0.5.2.1 due to a lack of anti-CSRF tokens or validation on administrative endpoints. Specifically, the user creation component at 'admin/index.php?mode=user&action=new' does not verify the intent of the request. A remote attacker can exploit this by hosting a malicious page with a hidden auto-submitting HTML form. If an authenticated administrator visits this page, the browser will execute a POST request to the CMS, creating a new administrative user with attacker-defined credentials. This allows for full privilege escalation and persistent access to the CMS backend.

Affected products

  • bloofox bloofoxCMS 0.5.1.0 through 0.5.2.1

Timeline

  • 2020-12-18: disclosed: Initial discovery by researcher LiPeiYi
  • 2021-02-01: other: Exploit published on Exploit-DB
  • 2026-05-16: advisory: NVD/VulnCheck advisory published

References