index.php in eFiction before 2.0.7 allows remote attackers to bypass authentication and gain privileges by setting the (1) adminloggedin, (2) loggedin, and (3) level parameters to "1".
Exploit prediction scoring system (EPSS) score
EPSS Score 0.138
EPSS Ranking 94.0%