Description
|
|
A vulnerability has been identified in ACGVannu, which could be exploited by attackers to manipulate arbitrary data. This issue is due to an input validation error in the "templates/modif.html" script that does not validate the "id" parameter, which could be exploited by remote attackers to modify a user's profile and password.
Various SQL injection vulnerabilities have also been identified (e.g. the "id_mod" parameter in "templates/modif.html").
|