PT-2026-67819 · Unknown · Atlas-Livre
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Atlas-Livre (affected versions not specified)
Description
Improper access control exists within the admin controllers located under
Espace admin/controleur/. Unauthenticated attackers can bypass session-based authentication guards by sending raw HTTP requests that ignore redirects. This occurs because the PHP header() redirect function is not followed by an exit or die call, allowing subsequent code and database operations to execute regardless of the session state. Attackers can trigger destructive administrative actions, such as record deletion, by targeting controller endpoints using the supp GET parameter.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Atlas-Livre