CVE-2009-4174

CutePHP CuteNews <8b - Auth Bypass

Title source: llm
STIX 2.1

Description

The editnews module in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b, when magic_quotes_gpc is disabled, allows remote authenticated users with Journalist or Editor access to bypass administrative moderation and edit previously submitted articles via a modified id parameter in a doeditnews action.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Andrew Horton · textwebappsphp
https://www.exploit-db.com/exploits/33345

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/54236
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/507782/100/0/threaded
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/36971

Scores

EPSS 0.0109
EPSS Percentile 78.0%

Details

CWE
CWE-264
Status published
Products (2)
cutephp/cutenews 1.4.6
korn19/utf-8_cutenews 8
Published Dec 02, 2009
Tracked Since Feb 18, 2026