Описание
PVote before 1.9 does not authenticate users for restricted operations, which allows remote attackers to add or delete polls by modifying parameters to (1) add.php or (2) del.php.
Ссылки
- ExploitVendor Advisory
- Vendor Advisory
- PatchVendor Advisory
- ExploitPatchVendor Advisory
- ExploitVendor Advisory
- Vendor Advisory
- PatchVendor Advisory
- ExploitPatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:steve_korbett:pvote:1.0:*:*:*:*:*:*:*
cpe:2.3:a:steve_korbett:pvote:1.0a:*:*:*:*:*:*:*
cpe:2.3:a:steve_korbett:pvote:1.0b:*:*:*:*:*:*:*
cpe:2.3:a:steve_korbett:pvote:1.5:*:*:*:*:*:*:*
EPSS
Процентиль: 89%
0.05053
Низкий
5 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
больше 3 лет назад
PVote before 1.9 does not authenticate users for restricted operations, which allows remote attackers to add or delete polls by modifying parameters to (1) add.php or (2) del.php.
EPSS
Процентиль: 89%
0.05053
Низкий
5 Medium
CVSS2
Дефекты
NVD-CWE-Other