Access Control Bypass in OpenDocMan by Document Management Solutions
CVE-2014-1946
8.8HIGH
What is CVE-2014-1946?
OpenDocMan versions 1.2.7 and earlier suffer from a vulnerability that fails to properly validate allowed actions for users. This flaw enables remote authenticated users to bypass access restrictions and gain administrative privileges through a manipulated request sent to signup.php. This improper handling of user permissions can lead to significant security risks, allowing unauthorized users to gain control and manage sensitive information within the application.
