PT-2006-7182 · Pronews · Pronews
Published
2006-12-15
·
Updated
2008-09-05
·
CVE-2006-6580
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ProNews version 1.5
Description
The issue concerns a lack of permission checks in the admin/change.php file, allowing remote attackers to modify news items without proper authorization. This could enable attackers to add or delete information within an item, potentially having other impacts.
Recommendations
For ProNews version 1.5, consider implementing proper access controls to restrict modifications to authorized users until a patch is available. As a temporary workaround, restrict access to the admin/change.php file to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pronews