The DropDocuments plugin in KnowledgeTree before 3.5.4a allows remote authenticated users to gain administrative privileges via a certain sequence of "browse documents" and dashboard requests.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/47530 | vdb entry |
http://secunia.com/advisories/33277 | third party advisory patch vendor advisory |
http://issues.knowledgetree.com/browse/KTS-3921 | |
http://wiki.knowledgetree.com/Version_3.5.4a#Security | |
http://www.securityfocus.com/bid/32920 | vdb entry patch |