PT-2017-18888 · Bigtree · Bigtree Cms

Xfkxfk

·

Published

2017-06-02

·

Updated

2019-10-03

·

CVE-2017-9378

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions BigTree CMS versions prior to 4.2.19
Description The issue allows a user to delete their own account, which is supposed to be an admin-only action. This could have security implications as the admin may have other tasks to complete before a user is deleted, such as data backups.
Recommendations For BigTree CMS versions prior to 4.2.19, update to version 4.2.19 or later to prevent users from deleting their own accounts. As a temporary workaround, consider restricting access to the account deletion feature until the update is applied.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-9378

Affected Products

Bigtree Cms