Impact
Request input is not properly validated in plugin controller and can be used to access low-level API of Plugin class. Attacker can, for instance, alter database data.
Attacker must have "General setup" update rights to be able to perform this attack.
Patches
Upgrade to 10.0.3.
Workarounds
Remove front/plugin.form.php
script.
References
.
Impact
Request input is not properly validated in plugin controller and can be used to access low-level API of Plugin class. Attacker can, for instance, alter database data.
Attacker must have "General setup" update rights to be able to perform this attack.
Patches
Upgrade to 10.0.3.
Workarounds
Remove
front/plugin.form.php
script.References
.