vendor:
Fusion News
by:
SecurityFocus
7.5
CVSS
HIGH
Access Validation Error
20
CWE
Product Name: Fusion News
Affected Version From: 3.3
Affected Version To: 3.3
Patch Exists: NO
Related CWE: N/A
CPE: Fusion News
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
Fusion News Access Validation Error
Fusion News is prone to an access validation error allowing a user to add arbitrary user/administrator accounts through manipulating URI parameters. Successful exploitation of this error may allow a user to compromise a vulnerable system by gaining administrative privileges.
Mitigation:
Ensure that access validation is properly implemented and enforced.