ZeroHour

CVE-2017-14231

PoC
CVSS 3.0
5.3 medium
EPSS
1%p71
Published
()
Modified
Description

GeniXCMS before 1.1.0 allows remote attackers to cause a denial of service (account blockage) by leveraging the mishandling of certain username substring relationships, such as the admin username versus the admin username, related to register.php, User.class.php, and Type.class.php.

Vendors
genixcms
Products
genixcms
Weakness
CWE-20
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

In the news

No ingested article mentions this CVE yet.