Butterfly Organizer 2.0.0 allows remote attackers to (1) delete arbitrary categories via a modified tablehere parameter to category-delete.php with the is_js_confirmed parameter set to 1, or (2) delete arbitrary accounts via the mytable parameter to delete.php.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://www.exploit-db.com/exploits/5800 | exploit |
http://www.securityfocus.com/bid/29703 | vdb entry exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/43067 | vdb entry |