Mavili Guestbook, as released in November 2007, allows remote attackers to edit, delete, and approve arbitrary messages via a direct request to (1) edit.asp, (2) delete.asp, or (3) approve.asp.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.