admin.php in Frax.dk Php Recommend 1.3 and earlier does...
High severity
Unreviewed
Published
May 2, 2022
to the GitHub Advisory Database
•
Updated Jan 31, 2023
Description
Published by the National Vulnerability Database
May 22, 2009
Published to the GitHub Advisory Database
May 2, 2022
Last updated
Jan 31, 2023
admin.php in Frax.dk Php Recommend 1.3 and earlier does not require authentication when the user password is changed, which allows remote attackers to gain administrative privileges via modified form_admin_user and form_admin_pass parameters.
References