mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-07 11:06:19 +00:00
939 B
939 B
CVE-2020-13474
Description
In NCH Express Accounts 8.24 and earlier, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as Add/Edit users.
POC
Reference
- https://cvewalkthrough.com/cve-2020-13474-nch-express-accounts-privilege-escalation/
- https://cvewalkthrough.com/cve-2020-13474-nch-express-accounts-privilege-escalation/
- https://tejaspingulkar.blogspot.com/2020/12/cve-2020-13474-nch-express-accounts.html
- https://tejaspingulkar.blogspot.com/2020/12/cve-2020-13474-nch-express-accounts.html
Github
No PoCs found on GitHub currently.