Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40443
HistoryMay 09, 2023 - 11:15 a.m.

Incorrect Authorization

2023-05-0911:15:13
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9
kiwitcms
incorrect authorization
email validation
admin page
account registration

EPSS

0.001

Percentile

42.2%

kiwitcms is vulnerable to Incorrect Authorization. The vulnerability exists in email parameter of admin.py because it does not properly validate email addresses in the admin page, which allows an attacker to change an email address without verifying ownership during account registration.

EPSS

0.001

Percentile

42.2%

Related for VERACODE:40443