Описание
DropAFew before 0.2.1 does not require authorization for certain privileged actions, which allows remote attackers to (1) view the logged calorie information of arbitrary users via the id parameter in editlogcal.php, (2) add arbitrary links via links.php, or (3) create arbitrary users via newaccount2.php.
Ссылки
- Vendor Advisory
- Patch
- Exploit
- Vendor Advisory
- Vendor Advisory
- Patch
- Exploit
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.2 (включая)
cpe:2.3:a:dropafew:dropafew:*:*:*:*:*:*:*:*
EPSS
Процентиль: 89%
0.04597
Низкий
6.4 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
DropAFew before 0.2.1 does not require authorization for certain privileged actions, which allows remote attackers to (1) view the logged calorie information of arbitrary users via the id parameter in editlogcal.php, (2) add arbitrary links via links.php, or (3) create arbitrary users via newaccount2.php.
EPSS
Процентиль: 89%
0.04597
Низкий
6.4 Medium
CVSS2
Дефекты
NVD-CWE-Other