The WHMCS Reseller Module V2 2.0.2 in Softaculous Virtualizor before 2.9.1.0 does not verify the user correctly, which allows remote authenticated users to control other virtual machines managed by Virtualizor by accessing a modified URL.
Weaknesses in this category are related to improper assignment or handling of permissions.
Link | Tags |
---|---|
https://gist.github.com/sedrubal/a83fa22f1091025a5c1a14aabd711ad7 | |
http://www.virtualizor.com/blog/?p=1551 | patch vendor advisory |