cp_memberedit.php in LightBlog 8.4.1.1 does not check for administrative credentials when processing an admin action, which allows remote authenticated users to increase the privileges of any account.
Publication date: Thu, 11 Oct 2007 15:17:00 +0000