Home
Description
Incorrect access control in laskBlog v2.6.1 allows attackers to arbitrarily delete user accounts via a crafted request.
References
github.com/DogukanUrker/flaskBlog/issues/130
gist.github.com/coleak2021/77895b7a7b335ae17eb57390f4a94917