Navigate CMS 2.8.7 contains a cross-site request forgery vulnerability that allows attackers to upload malicious extensions through a crafted HTML page. Attackers can trick authenticated administrators into executing arbitrary file uploads by leveraging the extension upload functionality without additional validation.
References
| Link | Resource |
|---|---|
| https://sourceforge.net/projects/navigatecms | Product |
| https://www.exploit-db.com/exploits/48548 | Exploit Third Party Advisory VDB Entry |
| https://www.navigatecms.com/en/home | Product |
| https://www.vulncheck.com/advisories/navigate-cms-cross-site-request-forgery | Broken Link |
Configurations
History
No history.
Information
Published : 2026-01-30 23:16
Updated : 2026-02-13 17:51
NVD link : CVE-2020-37054
Mitre link : CVE-2020-37054
CVE.ORG link : CVE-2020-37054
JSON object : View
Products Affected
naviwebs
- navigate_cms
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
