PT-2018-16897 · Zuuse · Zuuse Beims Contractorweb
Publicado
2018-01-15
·
Atualizado
2019-10-03
·
CVE-2018-5328
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ZUUSE BEIMS ContractorWeb .NET version 5.18.0.0
Description
The issue allows access to various privileged modules, such as "UserManagement", without properly authenticating the user. This can be exploited by an attacker to perform unauthorized actions, for example, by accessing the "Edit User Details" functionality.
Recommendations
For version 5.18.0.0, consider restricting access to the /UserManagement/ module until a proper authentication mechanism is implemented to prevent unauthorized actions. As a temporary workaround, restrict access to the "Edit User Details" functionality to minimize the risk of exploitation.
Exploit
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Zuuse Beims Contractorweb