HIGH
Lightweight news portal (LNP) 1.0b does not properly restrict access to administrator functionality, which allows remote attackers to gain administrator privileges via direct requests to admin.php with the (1) potd_delete, (2) potd, (3) vote_update, (4) vote, or (5) modifynews actions
Published Sep 8, 2009
7.5
HIGHCVSS 2.0
EPSS 2.29%
Description
Affected products
Remediation
Metrics
References (3)
Change history (0)
No recorded changes yet.