#VU25801 Permissions, Privileges, and Access Controls in RegistrationMagic - Custom Registration Forms and User Login - CVE-2020-9456

 

#VU25801 Permissions, Privileges, and Access Controls in RegistrationMagic - Custom Registration Forms and User Login - CVE-2020-9456

Published: March 6, 2020


Vulnerability identifier: #VU25801
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/U:Amber
CVE-ID: CVE-2020-9456
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
RegistrationMagic - Custom Registration Forms and User Login
Software vendor:
Registrationmagic

Description

The vulnerability allows a remote user to escalate privileges on the system.

The vulnerability exists due to insufficient capability checks or nonces for functions in the plugin used for administrative purposes. A remote user can send a specially crafted request with the "rm_slug" $_POST parameter set to "rm_user_edit" and the "user_id" parameter set to the user’s ID (which can typically be obtained from the user’s profile page) and change the user’s role to administrator.


Remediation

Install updates from vendor's website.

External links