The Admin Control Panel in Rianxosencabos CMS 0.9 does not require administrator privileges, which allows remote authenticated users to (1) change a user's privileges, (2) delete a user account, or perform unspecified other administrative actions via vectors involving an admin lista action to the default URI, possibly related to useradmin.php.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/31296 | vdb entry exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/45290 | vdb entry |
https://www.exploit-db.com/exploits/6513 | exploit |
http://securityreason.com/securityalert/4311 | third party advisory |