An issue in Mojoportal v2.7.0.0 allows an unauthenticated attacker to register a new user even if the Allow User Registrations feature is disabled.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://www.mojoportal.com/ | product |
https://github.com/blakduk/Advisories/blob/main/Mojoportal/README.md | third party advisory exploit |