HIGH
admin/edit_user.php in KerviNet Forum 1.1 and earlier does not require administrative authentication, which allows remote attackers to delete arbitrary accounts and conduct SQL injection attacks via the del_user_id parameter
Published Jul 5, 2009
7.5
HIGHCVSS 2.0
EPSS 1.03%
Description
Affected products
Remediation
Metrics
References (1)
Change history (0)
No recorded changes yet.