cve/2020/CVE-2020-6949.md

18 lines
662 B
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2020-6949](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6949)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
A privilege escalation issue was discovered in the postUser function in HashBrown CMS through 1.3.3. An editor user can change the password hash of an admin user's account, or otherwise reconfigure that account.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/SexyBeast233/SecBooks