Closed schakko closed 2 months ago
The GET parameter id is not properly quoted when viewing next_ad_int_blog_profile_relationship. The attack is only possible if the following conditions are matched:
id
next_ad_int_blog_profile_relationship
manage_network
The GET parameter
id
is not properly quoted when viewingnext_ad_int_blog_profile_relationship
. The attack is only possible if the following conditions are matched:manage_network
capabilities