CVE-2018-15833

In Vanilla before 2.6.1, the polling functionality allows Insecure Direct Object Reference (IDOR) via the Poll ID, leading to the ability of a single user to select multiple Poll Options (e.g., vote for multiple items).
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:vanillaforums:vanilla_forums:*:*:*:*:*:*:*:*

Information

Published : 2018-08-26 10:29

Updated : 2020-08-24 10:37


NVD link : CVE-2018-15833

Mitre link : CVE-2018-15833


JSON object : View

CWE
CWE-639

Authorization Bypass Through User-Controlled Key

Advertisement

dedicated server usa

Products Affected

vanillaforums

  • vanilla_forums