PT-2012-3573 · Autoform · Autoform Pdm Archive

David Elze

·

Publicado

2012-06-13

·

Atualizado

2012-09-29

·

CVE-2012-1828

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions AutoFORM PDM Archive versions prior to 7.1
Description The issue concerns the lack of authorization requirements for administrative functions, allowing remote authenticated users to perform administrative actions. This can be achieved by leveraging knowledge of a hidden function, such as the password-change function.
Recommendations For versions prior to 7.1, update to version 7.1 or later to resolve the issue. As a temporary workaround, consider restricting access to administrative functions to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-1828

Produtos afetados

Autoform Pdm Archive