User Account Creation Vulnerability in Elgg by Curverider
CVE-2012-6562

Currently unrated

Key Information:

Vendor

Elgg

Status
Vendor
CVE Published:
23 May 2013

What is CVE-2012-6562?

The Elgg application, specifically in engine/lib/users.php, contains a flaw that fails to properly enforce user permissions for the user addition action. This weakness may allow remote attackers to exploit the system, resulting in the unauthorized creation of user accounts. The vulnerability exists in versions of Elgg prior to 1.8.5, necessitating an update to mitigate potential abuse.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.