Описание
system/message.php in Admin News Tools 2.5 does not properly restrict access, which allows remote attackers to post news messages via a direct request.
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:adminnewstools:admin_news_tools:2.5:*:*:*:*:*:*:*
EPSS
Процентиль: 83%
0.0242
Низкий
7.5 High
CVSS2
Дефекты
CWE-264
Связанные уязвимости
github
больше 4 лет назад
system/message.php in Admin News Tools 2.5 does not properly restrict access, which allows remote attackers to post news messages via a direct request.
EPSS
Процентиль: 83%
0.0242
Низкий
7.5 High
CVSS2
Дефекты
CWE-264