bypass old password with array in /admin/account-user-email.php
Low
R
Revive Adserver
Submitted None
Actions:
Reported by
hoangn14
Vulnerability Details
Technical details and impact analysis
### Short Description
- attacker maybe change email or password without enter old password with array param.
- version:revive-adserver-5.0.4
- os :window
### POC
{F712486}
## Impact
attacker maybe change email or password without enter old password
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Array Index Underflow