thyseus / yii-user-management

a user management module collection for the yii framework
186 stars 122 forks source link

Critical Security - Privilege Scalation #212

Closed iConn closed 7 years ago

iConn commented 7 years ago

Any user can tamper the update (insert, registration and so on) request, for privilege scalation, setting the YumUser[superuser] parameter to 1.