Описание
approve.php in Img Pals Photo Host 1.0 does not authenticate requests, which allows remote attackers to change the activation of administrators via the u parameter in an (1) app0 (disable) or (2) app1 (enable) action.
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:imgpals:img_pals_photo_host:1.0:*:*:*:*:*:*:*
EPSS
Процентиль: 85%
0.02626
Низкий
6.4 Medium
CVSS2
Дефекты
CWE-287
Связанные уязвимости
github
больше 3 лет назад
approve.php in Img Pals Photo Host 1.0 does not authenticate requests, which allows remote attackers to change the activation of administrators via the u parameter in an (1) app0 (disable) or (2) app1 (enable) action.
EPSS
Процентиль: 85%
0.02626
Низкий
6.4 Medium
CVSS2
Дефекты
CWE-287