up.time 7.5.0 Superadmin Privilege Escalation

Discussion in 'News Aggregator' started by Packet Storm, 24 Aug 2015.

  1. Packet Storm

    Packet Storm Guest

    up.time suffers from a privilege escalation issue. A normal user can elevate his/her privileges by sending a POST request setting the parameter 'userroleid' to 1. Cross site request forgery can be used to exploit this attack.

    Continue reading...
     

Share This Page

Loading...