CVE-2020-6949
Summary
| CVE | CVE-2020-6949 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-01-13 19:15:00 UTC |
| Updated | 2020-01-17 16:09:00 UTC |
| Description | A privilege escalation issue was discovered in the postUser function in HashBrown CMS through 1.3.3. An editor user can change the password hash of an admin user's account, or otherwise reconfigure that account. |
Risk And Classification
Problem Types: CWE-269
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Hashbrowncms | Hashbrown Cms | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| vulnerability that editor user can change admin user's password · Issue #327 · HashBrownCMS/hashbrown-cms · GitHub | MISC | github.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.