vendor:
myNewsletter
by:
FarhadKey
7,5
CVSS
HIGH
Login Bypass
287
CWE
Product Name: myNewsletter
Affected Version From: 1.1.2
Affected Version To: 1.1.2
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
KAPDA.ir — myNewsletter <= 1.1.2 Login bypass exploit
A login bypass vulnerability exists in myNewsletter version 1.1.2. An attacker can exploit this vulnerability by changing the action in the source code and submitting it. This will allow the attacker to bypass the authentication process and gain access to the application.
Mitigation:
Upgrade to the latest version of myNewsletter.