CVE-2008-7172

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
08/09/2009
Last modified:
09/04/2025

Description

Lightweight news portal (LNP) 1.0b does not properly restrict access to administrator functionality, which allows remote attackers to gain administrator privileges via direct requests to admin.php with the (1) potd_delete, (2) potd, (3) vote_update, (4) vote, or (5) modifynews actions.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:yanick_bourbeau:lightweight_news_portal:1.0b:*:*:*:*:*:*:*