PT-2007-1966 · Project · Office Project
Publicado
2007-01-26
·
Atualizado
2017-07-29
·
CVE-2007-0506
CVSS v2.0
6.0
Média
| Vetor | AV:N/AC:M/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Project issue tracking versions 4.7.0 through 5.x before 20070123
Description
The issue allows remote authenticated users to bypass other access control modules. This is achieved by guessing the filename to obtain attached files and by making direct requests to obtain issue information. The
project issue access function is involved in this issue.Recommendations
For versions 4.7.0 through 5.x before 20070123, consider restricting access to the
project issue access function until a fix is available. Additionally, limiting direct requests to issue information and securing file attachments can help mitigate the risk.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Office Project