phpMyFAQ before 2.8.13 allows remote authenticated users with admin privileges to bypass authorization via a crafted instance ID parameter.
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
http://techdefencelabs.com/security-advisories.html | third party advisory |
https://www.phpmyfaq.de/security/advisory-2014-09-16 | vendor advisory |