myaccount.php in Easy Scripts Answer and Question Script allows remote attackers to remove arbitrary user accounts via a modified userid parameter without specifying any additional fields.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://www.exploit-db.com/exploits/8690 | exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/50627 | vdb entry |
http://osvdb.org/54586 | vdb entry |