Unrated severityNVD Advisory· Published Aug 26, 2018· Updated Aug 5, 2024
CVE-2018-15833
CVE-2018-15833
Description
In Vanilla before 2.6.1, the polling functionality allows Insecure Direct Object Reference (IDOR) via the Poll ID, leading to the ability of a single user to select multiple Poll Options (e.g., vote for multiple items).
Affected products
2<2.6.1+ 1 more
- (no CPE)range: <2.6.1
- (no CPE)range: <2.6.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- hackerone.com/reports/326434mitrex_refsource_MISC
- open.vanillaforums.com/discussion/36559mitrex_refsource_MISC
- twitter.com/viperbluff/status/1033067882941304832mitrex_refsource_MISC
- twitter.com/viperbluff/status/1033640333890834433mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.