CVE-2013-7196
static/ajax.php in PHPFox 3.7.3, 3.7.4, and 3.7.5 allows remote authenticated users to bypass intended "Only Me" restrictions and comment on a private publication via a request with a modified val[item_id] parameter for the publication.
View on NVDSeverity
N/A
EPSS
Probability of exploitation (next 30 days): 0.0271 (2.7%)
Percentile: 86.0%
EPSS: 2026-05-06
Affects
phpfox:phpfoxTechnical description
static/ajax.php in PHPFox 3.7.3, 3.7.4, and 3.7.5 allows remote authenticated users to bypass intended "Only Me" restrictions and comment on a private publication via a request with a modified val[item_id] parameter for the publication.
Published: 4/18/2014, 10:14:35 PM
Last modified: 5/6/2026, 10:30:45 PM
References
- http://www.securityfocus.com/archive/1/531745/100/0/threaded
- http://www.securityfocus.com/bid/66677
- https://exchange.xforce.ibmcloud.com/vulnerabilities/92336
- http://www.securityfocus.com/archive/1/531745/100/0/threaded
- http://www.securityfocus.com/bid/66677
- https://exchange.xforce.ibmcloud.com/vulnerabilities/92336