← Vulnerability feed

Vulnerability record · CVE-2020-14043 · published 24 August 2020

CVE-2020-14043: Codiad cross-site request forgery vulnerability

CCodiad · Codiad

** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Side Request Forgery (CSRF) vulnerability was found in Codiad v1.7.8 and later. The request to download a plugin from the marketplace is only available to admin users and it isn't CSRF protected in components/market/controller.php. This might cause admins to make a vulnerable request without them knowing and result in remote code execution. NOTE: the vendor states "Codiad is no longer under active maintenance by core contributors."

8.8 CVSS 3.1 High EPSS 1.5% · top 25.9% CWE-352 · Cross-site request forgery
8.8CVSS 3.1 base score, v2 6.8
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Side Request Forgery (CSRF) vulnerability was found in Codiad v1.7.8 and later. The request to download a plugin from the marketplace is only available to admin users and it isn't CSRF protected in components/market/controller.php. This might cause admins to make a vulnerable request without them knowing and result in remote code execution. NOTE: the vendor states "Codiad is no longer under active maintenance by core contributors."

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-14043 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-19208Codiad code injection vulnerabilityCodiad Web IDE through 2.8.4 allows PHP Code injection.EPSS 19%9.8CVE-2018-14009Codiad improper input validation vulnerabilityCodiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689.EPSS 38%9.8CVE-2017-11366Codiad os command injection vulnerabilitycomponents/filemanager/class.filemanager.php in Codiad before 2.8.4 is vulnerable to remote command execution because shell commands can be embedded …EPSS 7.5%7.5CVE-2017-20178Codiad information exposure vulnerability** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Codiad 2.8.0. It has been rated as problematic. Affected by this issue is the function s…EPSS 0.68%7.5CVE-2020-23355Codiad vulnerability** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Codiad 2.8.4 /componetns/user/class.user.php:Authenticate() is vulnerable in magic hash authentication bypa…EPSS 0.99%7.5CVE-2017-1000125Codiad incorrect permission assignment vulnerabilityCodiad(full version) is vulnerable to write anything to configure file in the installation resulting upload a webshell.EPSS 0.92%7.2CVE-2020-14044Codiad server-side request forgery (ssrf) vulnerability** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Server-Side Request Forgery (SSRF) vulnerability was found in Codiad v1.7.8 and later. A user with admin …EPSS 3.2%7.2CVE-2018-19423Codiad unrestricted file upload vulnerabilityCodiad 2.8.4 allows remote authenticated administrators to execute arbitrary code by uploading an executable file.EPSS 18%

Source: NIST National Vulnerability Database (record CVE-2020-14043), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.