PT-2007-3914 · Rsa · Rsauction
Publicado
2007-05-11
·
Atualizado
2017-07-29
·
CVE-2007-2595
CVSS v2.0
6.5
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
RSAuction version 2.73.1.3
Description
The issue allows remote authenticated users to change their account status from Suspended to Active by directly requesting the activation URL provided during account registration.
Recommendations
For RSAuction version 2.73.1.3, consider restricting access to the account activation URL to prevent unauthorized account status changes until a proper fix is applied.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Rsauction