glFusion CMS 1.7.9 is affected by an access control vulnerability via /public_html/users.php.
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Link | Tags |
---|---|
https://github.com/glFusion/glfusion/issues/487 | third party advisory issue tracking exploit |