Leed (Light Feed), possibly prior to 1.5 Stable, allows remote malicious users to bypass authorization via vectors related to the (1) importForm, (2) importFeed, (3) addFavorite, or (4) removeFavorite actions in action.php.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
idleman leed |