Vulnerabilities (CVE)

Filtered by vendor Metadot Subscribe
Filtered by product Metadot Portal Server
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-4458 1 Metadot 1 Metadot Portal Server 2024-02-04 9.0 HIGH N/A
Group.pm in Metadot Portal Server 6.4.4 and earlier does not properly reset the $IS_OWNER, $IS_ADMIN, and $IS_MANAGER global variables when performing checks for special privileges, which allows users to gain administrator privileges by adding themselves to the SITE_MGR group.