{"id":"CVE-2020-19964","title":"A Cross Site Request Forgery (CSRF) vulnerability was discovered in PHPMyWind 5.6 which allows attackers to create a new administrator account without authentication.","summary":"A Cross Site Request Forgery (CSRF) vulnerability was discovered in PHPMyWind 5.6 which allows attackers to create a new administrator account without authentication.","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","cwe":["CWE-352"],"vendor":"phpmywind","product":"phpmywind","affected":["phpmywind = 5.6"],"published":"2021-10-14","updated":"2026-07-05","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2020-19964","references":[{"url":"https://github.com/gaozhifeng/PHPMyWind","label":"cve@mitre.org"},{"url":"https://github.com/gaozhifeng/PHPMyWind/issues/9","label":"cve@mitre.org"},{"url":"http://phpmywind.com","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/gaozhifeng/PHPMyWind","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/gaozhifeng/PHPMyWind/issues/9","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00517,"epssPercentile":0.42834,"ingestedAt":"2026-07-06T17:03:23.594Z","slug":"CVE-2020-19964","body":"## Overview\n\nA Cross Site Request Forgery (CSRF) vulnerability was discovered in PHPMyWind 5.6 which allows attackers to create a new administrator account without authentication.\n\n## Affected\n\n- `phpmywind = 5.6`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}