Permissions, Privileges, and Access Controls in Hybrid Composer - #VU19198
Published: July 16, 2019
Hybrid Composer
Detailed vulnerability description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to the function “hc_ajax_save_option” uses "update_option()" along with two parameters that come directly from user input. A remote attacker can gain admin access or inject arbitrary data on the affected system.
This vulnerability leads to Options Update.