Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-4174

Опубликовано: 02 дек. 2009
Источник: nvd
CVSS2: 6
EPSS Низкий

Описание

The editnews module in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b, when magic_quotes_gpc is disabled, allows remote authenticated users with Journalist or Editor access to bypass administrative moderation and edit previously submitted articles via a modified id parameter in a doeditnews action.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cutephp:cutenews:1.4.6:*:*:*:*:*:*:*
cpe:2.3:a:korn19:utf-8_cutenews:8:*:*:*:*:*:*:*

EPSS

Процентиль: 77%
0.01085
Низкий

6 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

github
почти 4 года назад

The editnews module in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b, when magic_quotes_gpc is disabled, allows remote authenticated users with Journalist or Editor access to bypass administrative moderation and edit previously submitted articles via a modified id parameter in a doeditnews action.

EPSS

Процентиль: 77%
0.01085
Низкий

6 Medium

CVSS2

Дефекты

CWE-264