Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3qh6-c633-q2hf

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The edit-profile page in Vanilla Forums before 2.1a32 allows remote authenticated users to modify arbitrary profile settings by replacing the UserID value during a man-in-the-middle attack, related to a "parameter manipulation" issue.

The edit-profile page in Vanilla Forums before 2.1a32 allows remote authenticated users to modify arbitrary profile settings by replacing the UserID value during a man-in-the-middle attack, related to a "parameter manipulation" issue.

EPSS

Процентиль: 77%
0.01022
Низкий

Связанные уязвимости

nvd
около 13 лет назад

The edit-profile page in Vanilla Forums before 2.1a32 allows remote authenticated users to modify arbitrary profile settings by replacing the UserID value during a man-in-the-middle attack, related to a "parameter manipulation" issue.

EPSS

Процентиль: 77%
0.01022
Низкий