Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fx9r-q6w5-g4wc

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

blocks/shoutbox_block.php in BtiTracker 1.4.4 does not verify user accounts, which allows remote attackers to post shoutbox entries as arbitrary users via a modified nick field.

blocks/shoutbox_block.php in BtiTracker 1.4.4 does not verify user accounts, which allows remote attackers to post shoutbox entries as arbitrary users via a modified nick field.

EPSS

Процентиль: 77%
0.01023
Низкий

Дефекты

CWE-287

Связанные уязвимости

nvd
около 18 лет назад

blocks/shoutbox_block.php in BtiTracker 1.4.4 does not verify user accounts, which allows remote attackers to post shoutbox entries as arbitrary users via a modified nick field.

EPSS

Процентиль: 77%
0.01023
Низкий

Дефекты

CWE-287