inc/elementz.php in aliTalk 1.9.1.1 does not properly...
High severity
Unreviewed
Published
May 1, 2022
to the GitHub Advisory Database
•
Updated Jan 31, 2023
Description
Published by the National Vulnerability Database
Jan 23, 2008
Published to the GitHub Advisory Database
May 1, 2022
Last updated
Jan 31, 2023
inc/elementz.php in aliTalk 1.9.1.1 does not properly verify authentication, which allows remote attackers to add an arbitrary user account via a modified lilil parameter, in conjunction with the ubild and pa parameters.
References