CVE-2022-26254

MEDIUM

Wowonder - IDOR

Title source: rule
STIX 2.1

Description

WoWonder The Ultimate PHP Social Network Platform v4.0.0 was discovered to contain an access control issue which allows unauthenticated attackers to arbitrarily change group ID names.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://youtu.be/b665r1ZfCg4

Scores

CVSS v3 5.3
EPSS 0.0077
EPSS Percentile 73.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-639
Status published
Products (1)
wowonder/wowonder 4.0
Published Mar 27, 2022
Tracked Since Feb 18, 2026