5
CVSSv2

CVE-2013-2629

Published: 23/12/2013 Updated: 14/01/2014
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Leed (Light Feed), possibly prior to 1.5 Stable, allows remote malicious users to bypass authorization via vectors related to the (1) importForm, (2) importFeed, (3) addFavorite, or (4) removeFavorite actions in action.php.

Vulnerable Product Search on Vulmon Subscribe to Product

idleman leed

Exploits

Leed suffers from authentication bypass, cross site request forgery, and remote SQL injection vulnerabilities ...