An issue was discovered in Cuppa CMS Versions Before 31...
High severity
Unreviewed
Published
Dec 15, 2021
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Dec 14, 2021
Published to the GitHub Advisory Database
Dec 15, 2021
Last updated
Jan 27, 2023
An issue was discovered in Cuppa CMS Versions Before 31 Jan 2021 allows authenticated attackers to gain escalated privileges via a crafted POST request using the user_group_id_field parameter.
References