Home
MEDIUM: 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:NDefault status
unaffected
0.12.2
affected
Description
All versions of askbot before and including 0.12.2 allow an attacker authenticated with normal user permissions to modify the profile picture of other application users.This issue affects askbot: 0.12.2.
Problem types
CWE-639 Authorization Bypass Through User-Controlled Key
Product status
0.12.2
Credits
Daniel Celis
References
fluidattacks.com/advisories/ghost
askbot.com/
github.com/...ommit/3da3d75f35204aa71633c7a315327ba39cb6295d