CVE-2020-37091 is a Cross-Site Request Forgery (CSRF) vulnerability in Maian Support Helpdesk version 4.3. This flaw allows unauthenticated attackers to create administrative accounts and upload arbitrary PHP files via the FAQ attachment system by crafting malicious HTML forms. With a CVSS score of 5.3 (Medium), the vulnerability has a low attack complexity and no user interaction is required, potentially leading to unauthorized access and system compromise. There is currently no evidence of active exploitation, and no public exploit code or community discussion has been identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Maian Media | Maian Support Helpdesk | 4.3CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.