SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because texteditor.php is not restricted.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://www.solarview.io/ | not applicable |
https://github.com/xiaosed/CVE-2023-29919/ | third party advisory exploit |