CVE-2019-14347

Severity CVSS v4.0:
Pending analysis
Type:
CWE-425 Direct Request ('Forced Browsing')
Publication date:
06/08/2019
Last modified:
03/03/2023

Description

Internal/Views/addUsers.php in Schben Adive 2.0.7 allows remote unprivileged users (editor or developer) to create an administrator account via admin/user/add, as demonstrated by a Python PoC script.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:schben:adive:*:*:*:*:*:*:*:* 2.0.7 (including)