Home
HIGH: 8.3 CVSS:3.1/AC:L/AV:N/A:L/C:H/I:H/PR:L/S:U/UI:N
Description
An Incorrect Access Control vulnerability in the user management component of ZwiiCMS up to v13.6.07 allows a remote, authenticated attacker to escalate their privileges. By sending a specially crafted HTTP request, a low-privilege user can access and modify the profile data of any other user, including administrators.
References
blog.nivel4.com/...de-alta-severidad-en-gestor-de-contenidos
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.