Incorrect access control in laskBlog v2.6.1 allows attackers to arbitrarily delete user accounts via a crafted request.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://github.com/DogukanUrker/flaskBlog/issues/130 | issue tracking third party advisory |
https://gist.github.com/coleak2021/77895b7a7b335ae17eb57390f4a94917 | third party advisory |