#VU29565 Improper access control in Security & Malware scan by CleanTalk
Published: July 7, 2020
Security & Malware scan by CleanTalk
CleanTalk Security
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in several AJAX actions in the “security-malware-firewall/inc/spbc-admin.php” script. A remote authenticated attacker can make unauthorised AJAX call which could lead to arbitrary file deletion/download and function call.