vendor:
Magic News Plus
by:
cijfer
7.5
CVSS
HIGH
Input Validation Flaw
CWE
Product Name: Magic News Plus
Affected Version From: 1.0.0
Affected Version To: 1.0.3
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2006
Magic News Plus <=1.0.3 Admin Pass Change Exploit
An input validation flaw exists within 'settings.php' of Magic News Plus which can lead to the changing of the administrative password. The flaw occurs in line 108 of 426 in the code. The exploit involves sending specific parameters to the application to change the password.
Mitigation:
The vendor should fix the input validation issue in the 'settings.php' file to prevent unauthorized password changes. Users should also ensure that their Magic News Plus installation is up to date to mitigate this vulnerability.