mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-09 15:15:46 +02:00
688 B
688 B
CVE-2012-6562
Description
engine/lib/users.php in Elgg before 1.8.5 does not properly specify permissions for the useradd action, which allows remote attackers to create arbitrary accounts.
POC
Reference
- http://elgg.org/getelgg.php?forward=elgg-1.8.5.zip
- http://elgg.org/getelgg.php?forward=elgg-1.8.5.zip
Github
No PoCs found on GitHub currently.