Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jh9g-5jwj-9gpm

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

ClipShare 2.6 does not properly restrict access to certain functionality, which allows remote attackers to change the profile of arbitrary users via a modified uid variable to siteadmin/useredit.php. NOTE: this can be used to recover the password of the user by using the modified e-mail address in the email parameter to recoverpass.php.

ClipShare 2.6 does not properly restrict access to certain functionality, which allows remote attackers to change the profile of arbitrary users via a modified uid variable to siteadmin/useredit.php. NOTE: this can be used to recover the password of the user by using the modified e-mail address in the email parameter to recoverpass.php.

EPSS

Процентиль: 88%
0.03628
Низкий

Связанные уязвимости

nvd
больше 16 лет назад

ClipShare 2.6 does not properly restrict access to certain functionality, which allows remote attackers to change the profile of arbitrary users via a modified uid variable to siteadmin/useredit.php. NOTE: this can be used to recover the password of the user by using the modified e-mail address in the email parameter to recoverpass.php.

EPSS

Процентиль: 88%
0.03628
Низкий