Submitty before v22.06.00 is vulnerable to Incorrect Access Control. An attacker can delete any post in the forum by modifying request parameter.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://github.com/Submitty/Submitty/pull/8032 | patch vendor advisory |
https://fuchai.net/cve/CVE-2023-43194 | third party advisory exploit |