vendor:
KDPics
by:
Unknown
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: KDPics
Affected Version From: 1.18
Affected Version To: 1.18 (other versions may also be affected)
Patch Exists: NO
Related CWE: Unknown
CPE: a:kdpics:kdpics:1.18
Platforms Tested:
Unknown
KDPics Remote Add Admin Vulnerability
The KDPics application is prone to an authentication bypass vulnerability that allows an attacker to add an administrative user. This vulnerability is due to inadequate access control mechanisms in the application. An attacker can exploit this vulnerability by sending a specially crafted request to the vulnerable application. Successful exploitation of this vulnerability could allow the attacker to compromise the application and the underlying computer. Other attacks are also possible.
Mitigation:
It is recommended to apply the latest security patches and updates to the KDPics application. Additionally, it is advised to implement strong access control mechanisms to prevent unauthorized access to administrative functionality.