#VU19198 Permissions, Privileges, and Access Controls in Hybrid Composer
Published: July 16, 2019
Hybrid Composer
Schiocco
Description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to the function “hc_ajax_save_option” uses "update_option()" along with two parameters that come directly from user input. A remote attacker can gain admin access or inject arbitrary data on the affected system.
This vulnerability leads to Options Update.