CVE-2020-6949

A privilege escalation issue was discovered in the postUser function in HashBrown CMS through 1.3.3. An editor user can change the password hash of an admin user's account, or otherwise reconfigure that account.
References
Link Resource
https://github.com/HashBrownCMS/hashbrown-cms/issues/327 Exploit Third Party Advisory
https://github.com/HashBrownCMS/hashbrown-cms/issues/327 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:hashbrowncms:hashbrown_cms:*:*:*:*:*:*:*:*

History

21 Nov 2024, 05:36

Type Values Removed Values Added
References () https://github.com/HashBrownCMS/hashbrown-cms/issues/327 - Exploit, Third Party Advisory () https://github.com/HashBrownCMS/hashbrown-cms/issues/327 - Exploit, Third Party Advisory

Information

Published : 2020-01-13 19:15

Updated : 2024-11-21 05:36


NVD link : CVE-2020-6949

Mitre link : CVE-2020-6949

CVE.ORG link : CVE-2020-6949


JSON object : View

Products Affected

hashbrowncms

  • hashbrown_cms
CWE
CWE-269

Improper Privilege Management