Code generated by PHP FormMail Generator may allow a remote unauthenticated user to bypass authentication in the to access the administrator panel by navigating directly to /admin.php?mod=admin&func=panel
The authentication scheme or implementation uses key data elements that are assumed to be immutable, but can be controlled or modified by the attacker.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Php_formmail_generator | Jqueryform | - (including) | - (including) |