PT-2005-1396 · Alt N · Alt-N Webadmin
David Alonso Pérez
·
Published
2005-01-28
·
Updated
2016-10-18
·
CVE-2005-0318
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Alt-N WebAdmin version 3.0.4
Description
The issue concerns improper validation of account edits by logged-in users. This allows remote authenticated users to edit other users' account information by modifying the
user parameter.Recommendations
For Alt-N WebAdmin version 3.0.4, consider restricting access to the user edit functionality until a proper fix is available, and avoid using the modified
user parameter in the affected API endpoint.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt-N Webadmin