Permissions, Privileges, and Access Controls in Hybrid Composer - #VU19198

 

Permissions, Privileges, and Access Controls in Hybrid Composer - #VU19198

Published: July 16, 2019


Vulnerability identifier: #VU19198
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to the function “hc_ajax_save_option” uses "update_option()" along with two parameters that come directly from user input. A remote attacker can gain admin access or inject arbitrary data on the affected system.

This vulnerability leads to Options Update.


Affected software

Hybrid Composer

Remediation

Install updates from vendor's website.

Hybrid Composer - update to 1.4.7

External References

Related Security Bulletins