message.php in Petitforum does not properly authenticate users, which allows remote attackers to impersonate forum users via a modified connect cookie.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://securitytracker.com/id?1006117 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/11359 | vdb entry |