A vulnerability in Site News 1.1 allows anyone to add or edit messages without having to authenticate as an administrator.