← Back

CVE-2022-46890

nvd nist
Published: Jan 19, 2023Modified: Apr 3, 2025

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

Weak access control in NexusPHP before 1.7.33 allows a remote authenticated user to edit any post in the forum (this is caused by a lack of checks performed by the /forums.php?action=post page).

Affected (1)

Products: Nexusphp: Nexusphp
1 product
Nexusphp
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.7.33

References (4)

Timeline

No history available yet.