CVE-2019-6126

HIGH

PHP Scripts Mall Advance Peer to Peer MLM Script <1.7.0 - Auth Bypass

Title source: llm
STIX 2.1

Description

The Admin Panel of PHP Scripts Mall Advance Peer to Peer MLM Script v1.7.0 allows remote attackers to bypass intended access restrictions by directly navigating to admin/dashboard.php or admin/user.php, as demonstrated by disclosure of information about users and staff.

Scores

CVSS v3 7.5
EPSS 0.0025
EPSS Percentile 48.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-425
Status published
Products (1)
advance_peer_to_peer_mlm_script_project/advance_peer_to_peer_mlm_script 1.7.0
Published Jan 11, 2019
Tracked Since Feb 18, 2026