AlstraSoft Live Support 1.21 sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to obtain administrative access via a direct request to admin/managesettings.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Live_support | Alstrasoft | 1.21 (including) | 1.21 (including) |