Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-77rw-7fvw-mgvf

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Yazd Discussion Forum before 3.0 beta does not properly manage forum permissions, which allows remote authenticated users to (1) reply to a message in an arbitrary forum, if authorized to create a message in any forum; and (2) perform certain unauthorized forum actions, related to an "error in how the permissions were assembled" that assigns extra permissions to users.

Yazd Discussion Forum before 3.0 beta does not properly manage forum permissions, which allows remote authenticated users to (1) reply to a message in an arbitrary forum, if authorized to create a message in any forum; and (2) perform certain unauthorized forum actions, related to an "error in how the permissions were assembled" that assigns extra permissions to users.

EPSS

Процентиль: 69%
0.00588
Низкий

Связанные уязвимости

nvd
больше 19 лет назад

Yazd Discussion Forum before 3.0 beta does not properly manage forum permissions, which allows remote authenticated users to (1) reply to a message in an arbitrary forum, if authorized to create a message in any forum; and (2) perform certain unauthorized forum actions, related to an "error in how the permissions were assembled" that assigns extra permissions to users.

EPSS

Процентиль: 69%
0.00588
Низкий