5.5
CVSSv2

CVE-2013-7195

Published: 18/04/2014 Updated: 09/10/2018
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N

Vulnerability Summary

PHPFox 3.7.3 and 3.7.4 allows remote authenticated users to bypass intended "Only Me" restrictions and "like" a publication via a request that specifies the ID for the publication.

Vulnerable Product Search on Vulmon Subscribe to Product

phpfox phpfox 3.7.4

phpfox phpfox 3.7.3

Exploits

PHPFox version 373, 374, and 375 suffer from an authorization bypass vulnerability ...

Github Repositories

POC

CVE I realy love it!!! All these publications were my first, today I have a slightly different view of how I should have built this path, well, it's true that we have improved over time CVE-2014-8469 PHPFOX XSS ADMINCP CVE-2013-7196 Comment on a publication set to "Only Me" CVE-2013-7195 Flag as "like" a publication set to "Only Me" CVE-2013