CVE Vulnerabilities

CVE-2020-19888

Improper Authentication

Published: Aug 24, 2020 | Modified: Nov 21, 2024
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

DBHcms v1.2.0 has an unauthorized operation vulnerability because theres no access control at line 175 of dbhcmspage.php for empty cache operation. This vulnerability can be exploited to empty a table.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
DbhcmsDbhcms_project1.2.0 (including)1.2.0 (including)

Potential Mitigations

References