The saveProfile function in PhpSlash 0.8.0 allows remote attackers to modify arbitrary profiles and gain privileges by modifying the author_id parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Phpslash | Phpslash | 0.8.0 (including) | 0.8.0 (including) |