elgg is vulnerable to Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Link | Tags |
---|---|
https://huntr.dev/bounties/a4df45d6-b739-4299-967f-c960b569383a | exploit third party advisory patch |
https://github.com/elgg/elgg/commit/d9fcad76ee380ea17edd61d13d0f87828ea3f744 | third party advisory patch |