admin/userform.php in RoomPHPlanning 1.5 does not require administrative credentials, which allows remote authenticated users to create new admin accounts.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/29377 | vdb entry exploit |
https://www.exploit-db.com/exploits/5674 | exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/42629 | vdb entry |
http://secunia.com/advisories/30376 | third party advisory vendor advisory |