Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6fp7-5j5p-8w56

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

RSMScript 1.21 allows remote attackers to bypass authentication and gain administrative privileges by setting the verified cookie to an arbitrary value and performing a direct request to (1) delete.php, (2) edit-submit.php, (3) edit.php, (4) submit.php, and (5) update.php, which bypasses the security check that is performed by verify.php.

RSMScript 1.21 allows remote attackers to bypass authentication and gain administrative privileges by setting the verified cookie to an arbitrary value and performing a direct request to (1) delete.php, (2) edit-submit.php, (3) edit.php, (4) submit.php, and (5) update.php, which bypasses the security check that is performed by verify.php.

EPSS

Процентиль: 83%
0.0194
Низкий

Дефекты

CWE-287

Связанные уязвимости

nvd
почти 17 лет назад

RSMScript 1.21 allows remote attackers to bypass authentication and gain administrative privileges by setting the verified cookie to an arbitrary value and performing a direct request to (1) delete.php, (2) edit-submit.php, (3) edit.php, (4) submit.php, and (5) update.php, which bypasses the security check that is performed by verify.php.

EPSS

Процентиль: 83%
0.0194
Низкий

Дефекты

CWE-287