CVE Vulnerabilities

CVE-2013-7196

Published: Apr 18, 2014 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

static/ajax.php in PHPFox 3.7.3, 3.7.4, and 3.7.5 allows remote authenticated users to bypass intended Only Me restrictions and comment on a private publication via a request with a modified val[item_id] parameter for the publication.

Affected Software

Name Vendor Start Version End Version
Phpfox Phpfox 3.7.3 (including) 3.7.3 (including)
Phpfox Phpfox 3.7.4 (including) 3.7.4 (including)
Phpfox Phpfox 3.7.5 (including) 3.7.5 (including)

References