PT-2009-6342 · Cutenews · Cutenews
Published
2009-12-02
·
Updated
2018-10-10
·
CVE-2009-4174
CVSS v2.0
6.0
Medium
| Vector | AV:N/AC:M/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
CuteNews versions 1.4.6 and prior to 8b (UTF-8 CuteNews)
Description
The issue allows remote authenticated users with certain access levels to bypass moderation and edit previously submitted articles. This is achieved by modifying the
id parameter in a "doeditnews" action when a specific PHP setting, magic quotes gpc, is disabled.Recommendations
For CuteNews version 1.4.6, consider disabling the
doeditnews action for users with Journalist or Editor access until a patch is available.
For UTF-8 CuteNews prior to version 8b, restrict access to the editnews module to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cutenews