Описание
DropAFew before 0.2.1 does not require authorization for certain privileged actions, which allows remote attackers to (1) view the logged calorie information of arbitrary users via the id parameter in editlogcal.php, (2) add arbitrary links via links.php, or (3) create arbitrary users via newaccount2.php.
Ссылки
- Vendor Advisory
- Patch
- Exploit
- Vendor Advisory
- Vendor Advisory
- Patch
- Exploit
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.2 (включая)
cpe:2.3:a:dropafew:dropafew:*:*:*:*:*:*:*:*
EPSS
Процентиль: 82%
0.02247
Низкий
6.4 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
больше 4 лет назад
DropAFew before 0.2.1 does not require authorization for certain privileged actions, which allows remote attackers to (1) view the logged calorie information of arbitrary users via the id parameter in editlogcal.php, (2) add arbitrary links via links.php, or (3) create arbitrary users via newaccount2.php.
EPSS
Процентиль: 82%
0.02247
Низкий
6.4 Medium
CVSS2
Дефекты
NVD-CWE-Other