Beveiligingsadvies

CVE-2014-1946

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2018-04-10 15:00:00
Laatst bijgewerkt 2024-08-06 09:58:14
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

OpenDocMan 1.2.7 and earlier does not properly validate allowed actions, which allows remote authenticated users to bypass an intended access restrictions and assign administrative privileges to themselves via a crafted request to signup.php.