VDB
Sign up
MEDIUM5.3

GHSA-559c-w54x-8342

GeniXCMS Mailbox validation logic vulnerability

Quick fix

GHSA-559c-w54x-8342 — genix/cms: upgrade to the fixed version with the command below.

composer require genix/cms:^1.1.0

Details

GeniXCMS 1.0.2 allows remote attackers to bypass the alertDanger MSG_USER_EMAIL_EXIST protection mechanism via a register.php?act=edit&id=1 request.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/genix/cms
Introduced in: 0Fixed in: 1.1.0
Fixcomposer require genix/cms:^1.1.0

References