Leed (Light Feed), possibly before 1.5 Stable, allows remote attackers to bypass authorization via vectors related to the (1) importForm, (2) importFeed, (3) addFavorite, or (4) removeFavorite actions in action.php.
References
Configurations
Information
Published : 2013-12-23 12:55
Updated : 2014-01-13 20:25
NVD link : CVE-2013-2629
Mitre link : CVE-2013-2629
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
idleman
- leed