vendor:
Messages Library 2.0
by:
Stack
7,5
CVSS
HIGH
Arbitrary Delete Message
20
CWE
Product Name: Messages Library 2.0
Affected Version From: 2.0
Affected Version To: 2.0
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Messages Library 2.0 <= Arbitrary Delete Message
This exploit allows an attacker to delete arbitrary messages from the Messages Library 2.0 application. The exploit requires the attacker to know the ContactID of the message they wish to delete. The exploit is achieved by sending a POST request to the sms.php file with the Action parameter set to Delete and the ID parameter set to the ContactID of the message to be deleted.
Mitigation:
Upgrade to the latest version of Messages Library 2.0