peter bassill · operator
$ cve CVE-2009-4174 JSON

CVE-2009-4174 EXPLOIT

6.0
MEDIUM · CVSS 2.0 · EPSS 1.6% (pctl 76)

Patch early

A public exploit exists.

Description

The editnews module in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b, when magic_quotes_gpc is disabled, allows remote authenticated users with Journalist or Editor access to bypass administrative moderation and edit previously submitted articles via a modified id parameter in a doeditnews action.

Scoring

CVSS6.0 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:S/C:P/I:P/A:P
EPSS1.65% — more likely to be exploited than 76% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2009-12-02
Last modified2026-06-16

Affected (2)

VendorProduct
cutephpcutenews
korn19utf-8 cutenews

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD