Remote authenticated users can bypass attachment-deletion restrictions in Discuz! DiscuzX X3.4

Remote authenticated users can bypass attachment-deletion restrictions in Discuz! DiscuzX X3.4

CVE-2018-5259 · MEDIUM Severity

AV:N/AC:L/AU:S/C:P/I:P/A:P

Discuz! DiscuzX X3.4 allows remote authenticated users to bypass intended attachment-deletion restrictions via a modified aid parameter.

Learn more about our User Device Pen Test.