Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pj6v-27vp-x3qw

Опубликовано: 29 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

admin.php in Newsletter ZWS allows remote attackers to gain administrative privileges via a list_user operation with the ulevel parameter set to 1 (administrator level), which lists all users and their passwords.

admin.php in Newsletter ZWS allows remote attackers to gain administrative privileges via a list_user operation with the ulevel parameter set to 1 (administrator level), which lists all users and their passwords.

EPSS

Процентиль: 87%
0.03512
Низкий

Связанные уязвимости

nvd
около 21 года назад

admin.php in Newsletter ZWS allows remote attackers to gain administrative privileges via a list_user operation with the ulevel parameter set to 1 (administrator level), which lists all users and their passwords.

EPSS

Процентиль: 87%
0.03512
Низкий