Vcard 2.9 and possibly other versions does not require authorization to run uninstall.php, which could allow remote attackers to uninstall Vcard and delete database tables via a direct request to uninstall.php.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Vcard | Belchior_foundry | 2.8 (including) | 2.8 (including) | 
| Vcard | Belchior_foundry | 2.9 (including) | 2.9 (including) |