Description
Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage.
Remediation
References
Related Vulnerabilities
ownCloud Improper Input Validation Vulnerability (CVE-2012-5610)
Oracle Application Server Other Vulnerability (CVE-2001-1216)
WordPress Plugin Widget Logic Cross-Site Request Forgery (5.9.0)
MediaWiki Other Vulnerability (CVE-2006-2895)
WordPress Plugin BAVOKO SEO Tools-All-in-One WordPress SEO Security Bypass (2.1.9.7)