CVE-2014-1946: Opendocman

High severity, CVSS 8.8. EPSS: 2.5% chance of exploitation in the next 30 days.

OpenDocMan 1.2.7 and earlier does not properly validate allowed actions, which allows remote authenticated users to bypass an intended access restrictions and assign administrative privileges to themselves via a crafted request to signup.php.

Affected products

Published 2018-04-10. Last modified 2026-06-17.