Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5xr2-3h2h-5cjv

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Flat Calendar 1.1 does not properly restrict access to administrative functions, which allows remote attackers to (1) add new events via calAdd.php, as reachable from admin/add.php, or (2) delete events via admin/deleteEvent.php. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product's security documentation.

Flat Calendar 1.1 does not properly restrict access to administrative functions, which allows remote attackers to (1) add new events via calAdd.php, as reachable from admin/add.php, or (2) delete events via admin/deleteEvent.php. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product's security documentation.

EPSS

Процентиль: 81%
0.01499
Низкий

Связанные уязвимости

nvd
почти 17 лет назад

Flat Calendar 1.1 does not properly restrict access to administrative functions, which allows remote attackers to (1) add new events via calAdd.php, as reachable from admin/add.php, or (2) delete events via admin/deleteEvent.php. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product's security documentation.

EPSS

Процентиль: 81%
0.01499
Низкий