An issue was discovered in ASPCMS 2.5.6. When registering ordinary users in the addUser function of the /member/reg.asp page, they can be registered with the super administrators GroupID directly.
References
Link | Resource |
---|---|
http://wooyun.org/bugs/wooyun-2015-091831 | VDB Entry Third Party Advisory |
https://www.seebug.org/vuldb/ssvid-96205 | Exploit Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2018-08-26T21:00:00
Updated: 2018-08-26T21:57:01
Reserved: 2018-08-26T00:00:00
Link: CVE-2018-15888
JSON object: View
NVD Information
Status : Analyzed
Published: 2018-08-26T21:29:00.563
Modified: 2018-11-06T15:37:15.330
Link: CVE-2018-15888
JSON object: View
Redhat Information
No data.
CWE