Posted by Andrey Stoykov on Jun 03
# Exploit Title: IDOR “Change Password” Functionality – adaptcmsv3.0.3
# Date: 06/2025
# Exploit Author: Andrey Stoykov
# Version: 3.0.3
# Tested on: Debian 12
# Blog: https://msecureltd.blogspot.com/
IDOR “Change Password” Functionality #1:
Steps to Reproduce:
1. Login as user with low privilege and visit profile page
2. Select “Edit Your Profile” and click “Submit”
3. Trap the HTTP POST request
4. Set…
– Read More – Full Disclosure