Description: Stephan Munz has discovered some vulnerabilities in Help Center Live, which can be exploited by malicious people to bypass certain security restrictions.
Various scripts including admin/departments.php and admin/operators.php do not properly restrict access to logged in users and can be exploited with an HTTP client that does not follow redirects.
Successful exploitation allows e.g. deleting administrative users without having valid user credentials.
The vulnerabilities are confirmed in versions 2.1.3a and 2.1.4. Prior versions may also be affected.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.