CVE-2018-5259: High severity comsenz discuzx vulnerability
Published Jan 8, 2018
·Updated
Discuz! DiscuzX X3.4 allows remote authenticated users to bypass intended attachment-deletion restrictions via a modified aid parameter.
Affected Software
1 affected component
Discuz DiscuzX=x3.4
Event History
Jan 8, 2018
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-5259?
CVE-2018-5259 has a medium severity rating as it allows authenticated users to bypass attachment-deletion restrictions.
2
What are the implications of CVE-2018-5259?
CVE-2018-5259 can result in unauthorized deletion of attachments, potentially affecting data integrity.
3
How do I fix CVE-2018-5259?
To fix CVE-2018-5259, ensure that you upgrade to a patched version of Discuz! DiscuzX that addresses this vulnerability.
4
Who is affected by CVE-2018-5259?
CVE-2018-5259 affects users of Discuz! DiscuzX version X3.4 who have remote authenticated access.
5
What is the nature of the vulnerability in CVE-2018-5259?
CVE-2018-5259 is a vulnerability that allows authenticated users to modify parameters to delete attachments without proper authorization.