Vulnerability Description
The Admin Panel of PHP Scripts Mall Advance Peer to Peer MLM Script v1.7.0 allows remote attackers to bypass intended access restrictions by directly navigating to admin/dashboard.php or admin/user.php, as demonstrated by disclosure of information about users and staff.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Advance Peer To Peer Mlm Script Project | Advance Peer To Peer Mlm Script | 1.7.0 |
Related Weaknesses (CWE)
References
- https://github.com/Mad-robot/CVE-List/blob/master/Advance%20Peer%20to%20Peer%20MThird Party Advisory
- https://github.com/Mad-robot/CVE-List/blob/master/Advance%20Peer%20to%20Peer%20MThird Party Advisory
FAQ
What is CVE-2019-6126?
CVE-2019-6126 is a vulnerability with a CVSS score of 7.5 (HIGH). The Admin Panel of PHP Scripts Mall Advance Peer to Peer MLM Script v1.7.0 allows remote attackers to bypass intended access restrictions by directly navigating to admin/dashboard.php or admin/user.ph...
How severe is CVE-2019-6126?
CVE-2019-6126 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-6126?
Check the references section above for vendor advisories and patch information. Affected products include: Advance Peer To Peer Mlm Script Project Advance Peer To Peer Mlm Script.