Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rm2r-h55q-8r58

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

zKup CMS 2.0 through 2.3 does not require administrative authentication for admin/configuration/modifier.php, which allows remote attackers to gain administrator privileges via a direct request, as demonstrated by adding a new administrator.

zKup CMS 2.0 through 2.3 does not require administrative authentication for admin/configuration/modifier.php, which allows remote attackers to gain administrator privileges via a direct request, as demonstrated by adding a new administrator.

EPSS

Процентиль: 92%
0.0816
Низкий

Дефекты

CWE-287

Связанные уязвимости

nvd
больше 16 лет назад

zKup CMS 2.0 through 2.3 does not require administrative authentication for admin/configuration/modifier.php, which allows remote attackers to gain administrator privileges via a direct request, as demonstrated by adding a new administrator.

EPSS

Процентиль: 92%
0.0816
Низкий

Дефекты

CWE-287