Leed (Light Feed), possibly before 1.5 Stable, allows remote attackers to bypass authorization via vectors related to the (1) importForm, (2) importFeed, (3) addFavorite, or (4) removeFavorite actions in action.php.
References
Configurations
History
21 Nov 2024, 01:52
Type | Values Removed | Values Added |
---|---|---|
References | () http://seclists.org/bugtraq/2013/Dec/107 - | |
References | () http://www.csnc.ch/misc/files/advisories/CSNC-2013-005-006-007_Leed_Multiple_vulns.txt - |
Information
Published : 2013-12-23 20:55
Updated : 2024-11-21 01:52
NVD link : CVE-2013-2629
Mitre link : CVE-2013-2629
CVE.ORG link : CVE-2013-2629
JSON object : View
Products Affected
idleman
- leed
CWE
CWE-20
Improper Input Validation