CVE-2020-6949

A privilege escalation issue was discovered in the postUser function in HashBrown CMS through 1.3.3. An editor user can change the password hash of an admin user's account, or otherwise reconfigure that account.
References
Link Resource
https://github.com/HashBrownCMS/hashbrown-cms/issues/327 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:hashbrowncms:hashbrown_cms:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2020-01-13 19:15

Updated : 2024-02-28 17:28


NVD link : CVE-2020-6949

Mitre link : CVE-2020-6949

CVE.ORG link : CVE-2020-6949


JSON object : View

Products Affected

hashbrowncms

  • hashbrown_cms
CWE
CWE-269

Improper Privilege Management