An issue in the save_users() function of Online Discussion Forum Site 1 allows unauthenticated attackers to arbitrarily create or update user accounts.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://www.sourcecodester.com/php/15337/online-discussion-forum-site-phpoop-free-source-code.html | third party advisory product |
https://github.com/bigzooooz/CVE-2022-31294 | third party advisory exploit |