Description
|
|
Multiple vulnerabilities have been identified in Psi-labs Photo Upload Share Script (psipuss), which could be exploited by attackers to execute arbitrary SQL queries and manipulate user profiles.
The first issue is caused by missing authentication checks in the "admin/editusers.php" script, which could be exploited by unauthenticated attackers to modify a user's profile (e.g. password or email address).
The second vulnerability is caused by an input validation error in the "admin/editusers.php" when processing the "Uid" parameter, which could be exploited by malicious people to conduct SQL injection attacks.
|