CVE-2021-37394
26.07.2021, 18:15
In RPCMS v1.8 and below, attackers can interact with API and change variable "role" to "admin" to achieve admin user registration.Enginsight
Vendor | Product | Version |
---|---|---|
rpcms | rpcms | 𝑥 ≤ 1.8 |
𝑥
= Vulnerable software versions
In RPCMS v1.8 and below, attackers can interact with API and change variable "role" to "admin" to achieve admin user registration.Enginsight
Vendor | Product | Version |
---|---|---|
rpcms | rpcms | 𝑥 ≤ 1.8 |