Description
index.php in Ryan Haudenschilt Family Connections (FCMS) before 0.9 allows remote attackers to access an arbitrary account by placing the account's name in the value of an fcms_login_id cookie. NOTE: this can be leveraged for code execution via a POST with PHP code in the content parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Yelp Review Slider SQL Injection (7.0)
Oracle JRE CVE-2024-21138 Vulnerability (CVE-2024-21138)
WordPress 4.1.x Multiple Vulnerabilities (4.1 - 4.1.9)
WordPress Plugin WooCommerce PHP Object Injection (3.1.0)
WordPress Plugin Magn WP Drag and Drop Upload Arbitrary File Upload (1.1.4)