CuteFlow 2.10.3 and 2.11.0_c does not properly restrict access to pages/edituser.php, which allows remote attackers to modify usernames and passwords via a direct request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cuteflow | Cuteflow | 2.10.3 (including) | 2.10.3 (including) |
Cuteflow | Cuteflow | 2.11.0_c (including) | 2.11.0_c (including) |