Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6g65-24hq-98xf

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

static/ajax.php in PHPFox 3.7.3, 3.7.4, and 3.7.5 allows remote authenticated users to bypass intended "Only Me" restrictions and comment on a private publication via a request with a modified val[item_id] parameter for the publication.

static/ajax.php in PHPFox 3.7.3, 3.7.4, and 3.7.5 allows remote authenticated users to bypass intended "Only Me" restrictions and comment on a private publication via a request with a modified val[item_id] parameter for the publication.

EPSS

Процентиль: 87%
0.03308
Низкий

Связанные уязвимости

nvd
почти 12 лет назад

static/ajax.php in PHPFox 3.7.3, 3.7.4, and 3.7.5 allows remote authenticated users to bypass intended "Only Me" restrictions and comment on a private publication via a request with a modified val[item_id] parameter for the publication.

EPSS

Процентиль: 87%
0.03308
Низкий