PT-2006-7182 · Pronews · Pronews

Published

2006-12-15

·

Updated

2008-09-05

·

CVE-2006-6580

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions ProNews version 1.5
Description The issue concerns a lack of permission checks in the admin/change.php file, allowing remote attackers to modify news items without proper authorization. This could enable attackers to add or delete information within an item, potentially having other impacts.
Recommendations For ProNews version 1.5, consider implementing proper access controls to restrict modifications to authorized users until a patch is available. As a temporary workaround, restrict access to the admin/change.php file to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-6580

Affected Products

Pronews