glFusion CMS v1.7.9 is affected by an arbitrary user impersonation vulnerability in /public_html/comment.php. The attacker can complete the attack remotely without interaction.
The product does not properly verify that the source of data or communication is valid.
Link | Tags |
---|---|
https://github.com/glFusion/glfusion/issues/482 | third party advisory issue tracking exploit |