Million Dollar Text Links 1.0 does not properly restrict administrator access to admin.home.php, which allows remote attackers to bypass intended restrictions and gain privileges via a direct request to admin.home.php after visiting admin.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Million_dollar_text_links | Kalptarudemos | 1.0 (including) | 1.0 (including) |