Lucene search

K
osvGoogleOSV:GHSA-C273-C6VG-4PV5
HistoryMay 24, 2022 - 12:01 a.m.

Publify has Improper Access Controls

2022-05-2400:01:48
Google
osv.dev
11
publify
access controls
user modification
admin articles
parameter manipulation
security issue

EPSS

0.001

Percentile

21.4%

A low-privileged user can modify and delete admin articles by changing the value of the article[id] parameter prior to 9.2.9.

EPSS

0.001

Percentile

21.4%