8.8
CVSSv3

CVE-2014-1946

Published: 10/04/2018 Updated: 26/04/2019
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

OpenDocMan 1.2.7 and previous versions does not properly validate allowed actions, which allows remote authenticated users to bypass an intended access restrictions and assign administrative privileges to themselves via a crafted request to signup.php.

Vulnerable Product Search on Vulmon Subscribe to Product

opendocman opendocman

Exploits

OpenDocMan versions 127 and below suffer from improper access control and remote SQL injection vulnerabilities ...