option_Update.asp in Carbon Communities 2.4 and earlier allows remote attackers to edit arbitrary member information via a modified ID field.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Carbon_communities | Carbon_communities | * | 2.4 (including) |
References