PT-2017-10996 · Tracker · Dtracker

Larry W. Cashdollar

+1

·

Publicado

2017-09-14

·

Atualizado

2019-10-03

·

CVE-2017-1002007

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions DTracker version 1.5
Description The issue concerns a lack of authorization check in the code, specifically in the dtracker/save mail.php file, which allows unauthorized injection of new contacts into the wp contact table.
Recommendations For DTracker version 1.5, consider temporarily restricting access to the dtracker/save mail.php file until a patch is available, and ensure that proper authorization checks are implemented to prevent unauthorized modifications to the wp contact table.

Exploit

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-1002007

Produtos afetados

Dtracker