Description
Pachno 1.0.6 contains an authentication bypass vulnerability in the runSwitchUser() action that allows authenticated low-privilege users to escalate privileges by manipulating the original_username cookie. Attackers can set the client-controlled original_username cookie to any value and request a switch to user ID 1 to obtain session tokens or password hashes belonging to administrator accounts.
Problem types
Authorization Bypass Through User-Controlled Key
Product status
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/
www.zeroscience.mk/en/vulnerabilities/ZSL-2026-5985.php (Zero Science Lab Disclosure)
www.vulncheck.com/...authentication-bypass-via-runswitchuser (VulnCheck Advisory: Pachno 1.0.6 Authentication Bypass via runSwitchUser())