ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-37217”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-37217
Published
2026-05-13
CVSS:
5.1
ShadowTrackr CVSS:
1.2
Summary:
Easy2Pilot 7 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized user accounts by tricking authenticated administrators into visiting malicious pages. Attackers can craft HTML forms targeting the admin.php?action=add_user endpoint with POST requests containing username and password parameters to create new administrative accounts without explicit user consent.