Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q6mr-4q5f-3vh6

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote attackers to modify arbitrary accounts via the (1) loginname, (2) password, (3) email, (4) firstname, or (5) lastname parameter.

admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote attackers to modify arbitrary accounts via the (1) loginname, (2) password, (3) email, (4) firstname, or (5) lastname parameter.

EPSS

Процентиль: 87%
0.034
Низкий

Связанные уязвимости

nvd
больше 16 лет назад

admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote attackers to modify arbitrary accounts via the (1) loginname, (2) password, (3) email, (4) firstname, or (5) lastname parameter.

EPSS

Процентиль: 87%
0.034
Низкий