Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Tyhko

#29826of 53,630
8.8Total CVSS
Vulnerabilities · 1
PT-2021-20316
8.8
2021-12-14
Cuppacms · Cuppacms · CVE-2021-3376
Name of the Vulnerable Software and Affected Versions: Cuppa CMS versions prior to 31 Jan 2021 Description: The issue allows authenticated attackers to gain escalated privileges via a crafted POST request using the `user group id field` parameter. Recommendations: For Cuppa CMS versions prior to 31 Jan 2021, consider restricting access to the `user group id field` parameter in POST requests until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.