VulnerabilityModified
CVE-2012-4926
approve.php in Img Pals Photo Host 1.0 does not authenticate requests, which allows remote attackers to change the activation of administrators via the u parameter in an (1) app0 (disable) or (2) app1 (enable) action.
MEDIUM 6.4EPSS 1.90%
Does this matter?
Lower severity and a low EPSS score (1.90%). Track it; it rarely justifies an emergency change on its own.
Description
approve.php in Img Pals Photo Host 1.0 does not authenticate requests, which allows remote attackers to change the activation of administrators via the u parameter in an (1) app0 (disable) or (2) app1 (enable) action.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
- EPSS
- 1.90% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- imgpals/img pals photo host
- Source
- cve@mitre.org
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.