Description
|
|
High-Tech Bridge has discovered two vulnerabilities in AContent, which can be exploited by malicious people to bypass certain security restrictions and conduct SQL injection attacks.
1) Input passed via the "field" POST parameter to user/index_inline_editor_submit.php is not properly sanitised before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
2) The application does not properly restrict access to user/index_inline_editor_submit.php, which can be exploited to change a user's password.
The vulnerabilities are confirmed in version 1.2. Other versions may also be affected.
|