profile.php in Silent Storm Portal 2.1 and 2.2 allows remote attackers to gain privileges by setting the mail parameter to 1, which is the value for an administrator.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Silent-storm_portal | Silent-storm | 2.1 (including) | 2.1 (including) |
Silent-storm_portal | Silent-storm | 2.2 (including) | 2.2 (including) |