Improper Authorization in ThinkSAAS v2.7 allows remote attackers to modify the description of any users photo via the photoid%5B%5D and photodesc%5B%5D parameters in the component index.php?app=photo.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Thinksaas | Thinksaas | 2.7 (including) | 2.7 (including) |