PT-2002-2480 · Phprojekt · Phprojekt
Published
2002-12-31
·
Updated
2017-07-11
·
CVE-2002-1758
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
PHProjekt versions 2.0 through 3.1
Description
The issue allows remote attackers to view or modify data by sending requests to certain scripts that do not verify if the user is logged in.
Recommendations
For PHProjekt versions 2.0 through 3.1, consider implementing proper authentication checks for all scripts to ensure that only logged-in users can access or modify data.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phprojekt