Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xv56-7cfh-4v8j

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Group.pm in Metadot Portal Server 6.4.4 and earlier does not properly reset the $IS_OWNER, $IS_ADMIN, and $IS_MANAGER global variables when performing checks for special privileges, which allows users to gain administrator privileges by adding themselves to the SITE_MGR group.

Group.pm in Metadot Portal Server 6.4.4 and earlier does not properly reset the $IS_OWNER, $IS_ADMIN, and $IS_MANAGER global variables when performing checks for special privileges, which allows users to gain administrator privileges by adding themselves to the SITE_MGR group.

EPSS

Процентиль: 82%
0.01719
Низкий

Связанные уязвимости

nvd
около 20 лет назад

Group.pm in Metadot Portal Server 6.4.4 and earlier does not properly reset the $IS_OWNER, $IS_ADMIN, and $IS_MANAGER global variables when performing checks for special privileges, which allows users to gain administrator privileges by adding themselves to the SITE_MGR group.

EPSS

Процентиль: 82%
0.01719
Низкий