CVE-2017-11681
Published Jul 27, 2017Incorrect Access Control vulnerability in Hashtopussy 0.4.0 allows remote authenticated users to execute actions that should only be available for administrative roles, as demonst…
Vendor/product archive
2 CVEs tagged to project_hashtopussy / hashtopussy — 0 Critical, 2 High, 0 Medium, 0 Low, 0 Unrated.
Incorrect Access Control vulnerability in Hashtopussy 0.4.0 allows remote authenticated users to execute actions that should only be available for administrative roles, as demonst…
Cross-Site Request Forgery (CSRF) exists in Hashtopussy 0.4.0, allowing an admin password change via users.php.