CVE-2013-7196 Information

Description

static/ajax.php in PHPFox 3.7.3 3.7.4 and 3.7.5 allows remote authenticated users to bypass intended \Only Me\ restrictions and comment on a private publication via a request with a modified val[item_id] parameter for the publication.

Reference

http://www.securityfocus.com/archive/1/531745/100/0/threaded http://www.securityfocus.com/bid/66677 https://exchange.xforce.ibmcloud.com/vulnerabilities/92336

Share on: