A privilege escalation issue was discovered in the postUser function in HashBrown CMS through 1.3.3. An editor user can change the password hash of an admin user's account, or otherwise reconfigure that account.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/HashBrownCMS/hashbrown-cms/issues/327 |
![]() ![]() |
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T09:18:02.522Z
Reserved: 2020-01-13T00:00:00
Link: CVE-2020-6949

No data.

Status : Modified
Published: 2020-01-13T19:15:12.930
Modified: 2024-11-21T05:36:22.553
Link: CVE-2020-6949

No data.