CuteFlow 2.10.3 and 2.11.0_c does not properly restrict access to pages/edituser.php, which allows remote attackers to modify usernames and passwords via a direct request.
Score: 0.0
Priority: Unclassified
Score: 0.01698
Percentile:
0.81474
CVSS v2 Score: 7.5
Severity: