vendor:
Pie Register
by:
Kacper Szurek
7.5
CVSS
HIGH
Privilege escalation
264
CWE
Product Name: Pie Register
Affected Version From: 2.0.13
Affected Version To: 2.0.13
Patch Exists: YES
Related CWE: CVE-2014-8802
CPE: a:pieregister:pie_register
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: WordPress
2014
Pie Register 2.0.13 Privilege escalation
Anyone can import CSV file. Pie Register will import users from this file. After importing, the user can activate the account and reset the password. This can be done by creating a CSV file with the details of the user and then importing it using a form. The user can then activate the account using a form and reset the password using the lost password feature.
Mitigation:
Update to version 2.0.14