CVE-2008-4245

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
25/09/2008
Last modified:
09/04/2025

Description

The Admin Control Panel in Rianxosencabos CMS 0.9 does not require administrator privileges, which allows remote authenticated users to (1) change a user's privileges, (2) delete a user account, or perform unspecified other administrative actions via vectors involving an admin lista action to the default URI, possibly related to useradmin.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rianxosencabos_cms:rianxosencabos_cms:0.9:*:*:*:*:*:*:*