PT-2009-6342 · Cutenews · Cutenews

Published

2009-12-02

·

Updated

2018-10-10

·

CVE-2009-4174

CVSS v2.0

6.0

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions CuteNews versions 1.4.6 and prior to 8b (UTF-8 CuteNews)
Description The issue allows remote authenticated users with certain access levels to bypass moderation and edit previously submitted articles. This is achieved by modifying the id parameter in a "doeditnews" action when a specific PHP setting, magic quotes gpc, is disabled.
Recommendations For CuteNews version 1.4.6, consider disabling the doeditnews action for users with Journalist or Editor access until a patch is available. For UTF-8 CuteNews prior to version 8b, restrict access to the editnews module to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-4174

Affected Products

Cutenews