baserCMS before 3.0.8 allows remote authenticated users to modify arbitrary user settings via a crafted request.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://basercms.net/security/JVN04855224 | vendor advisory |
http://jvndb.jvn.jp/jvndb/JVNDB-2015-000138 | third party advisory vendor advisory |
http://jvn.jp/en/jp/JVN04855224/index.html | third party advisory vendor advisory |