Vcard 2.9 and possibly other versions does not require authorization to run uninstall.php, which could allow remote attackers to uninstall Vcard and delete database tables via a direct request to uninstall.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Vcard | Belchior_foundry | 2.8 (including) | 2.8 (including) |
Vcard | Belchior_foundry | 2.9 (including) | 2.9 (including) |