CVE-2002-0588
MEDIUM 5.0EPSS 6.6%
PVote before 1.9 does not authenticate users for restricted operations, which allows remote attackers to add or delete polls by modifying parameters to (1) add.php or (2) del.php.
- CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N - EPSS
- 6.61% chance of exploitation in the next 30 days, 93th percentile
- Published
- 2002-06-11
- Updated
- 2024-08-08