CVE-2009-4174
The editnews module in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b, when magic_quotes_gpc is disabled, allows remote authenticated users with Journalist or Editor access to bypass administrative moderation and edit previously submitted articles via a modified id parameter in a doeditnews action.
- Affected products
- Cutenews
- Cutephp Cutenews
- = 1.4.6
- korn19 utf-8 Cutenews
- = 8
- Fix
- Available
- CVSS 2.0
- 6.0 MEDIUM
- EPSS
- 1.6% (75th percentile)
- Weakness
- CWE-264
- NVD status
- Modified
- Published
- 2009-12-02
CVE-2009-4174 at NVD
1 known exploit for CVE-2009-4174
Proof-of-concept code and exploit modules indexed by Sploitus