blocks/shoutbox_block.php in BtiTracker 1.4.4 does not verify user accounts, which allows remote attackers to post shoutbox entries as arbitrary users via a modified nick field.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Bti-tracker | Bti-tracker | * | 1.4.4 (including) |