Back

MEDIUM

vFairs 3.3 is affected by Insecure Permissions

Published May 26, 2021

Description

vFairs 3.3 is affected by Insecure Permissions. Any user logged in to a vFairs virtual conference or event can modify any other users profile information or profile picture. After receiving any user's unique identification number and their own, an HTTP POST request can be made update their profile description or supply a new profile image. This can lead to potential cross-site scripting attacks on any user, or upload malicious PHP webshells as "profile pictures." The user IDs can be easily determined by other responses from the API for an event or chat room.

Affected products

Remediation

No remediation recorded yet.

References (4)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published May 26, 2021
Updated Jul 9, 2026
Reserved Oct 7, 2020

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jul 9, 2026

Red Hat

No data

ENISA EUVD

Assigner mitre
Published May 26, 2021
Updated Jul 9, 2026

GitHub

No data