Incorrect access control in NexusPHP 1.5.beta5.20120707 allows unauthorized attackers to access published content.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://github.com/burpheart/CVE/blob/master/2020-08-13-03.md | third party advisory exploit |
https://nexusphp.org/2021/02/03/nexusphp-v1-6-0-beta2/ | release notes vendor advisory |
https://cwe.mitre.org/data/definitions/306.html | third party advisory |