Open Bulletin Board (OpenBB) 1.0.0 RC3 allows remote attackers to bypass authentication and access modifier options via a direct request to moderator.php with the action and ismod parameters.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openbb | Openbb | 1.0.0_rc1 (including) | 1.0.0_rc1 (including) |
Openbb | Openbb | 1.0.0_rc2 (including) | 1.0.0_rc2 (including) |
Openbb | Openbb | 1.0.0_rc3 (including) | 1.0.0_rc3 (including) |