Vulnerability Details CVE-2020-6949
A privilege escalation issue was discovered in the postUser function in HashBrown CMS through 1.3.3. An editor user can change the password hash of an admin user's account, or otherwise reconfigure that account.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 52.8%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.5
Products affected by CVE-2020-6949
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:-
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:0.10.0
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:0.10.1
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:0.10.2
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:0.10.3
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:0.6
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:0.7
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:0.7.1
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:0.7.2
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:0.8.0
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:0.8.1
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:0.9.0
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:0.9.2
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:0.9.3
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:0.9.4
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:0.9.5
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:0.9.6
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:0.9.7
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:0.9.9
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:1.0.0
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:1.0.1
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:1.0.2
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:1.0.3
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:1.0.4
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:1.0.5
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:1.0.6
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:1.0.7
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:1.1.0
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:1.1.1
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:1.1.2
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:1.1.3
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:1.1.4
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:1.2.0
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:1.2.1
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:1.2.2
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:1.3
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:1.3.1
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:1.3.2
-
cpe:2.3:a:hashbrowncms:hashbrown_cms:1.3.3