PT-2007-1966 · Project · Office Project
Published
2007-01-26
·
Updated
2017-07-29
·
CVE-2007-0506
CVSS v2.0
6.0
Medium
| Vector | AV:N/AC:M/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Project issue tracking versions 4.7.0 through 5.x before 20070123
Description
The issue allows remote authenticated users to bypass other access control modules. This is achieved by guessing the filename to obtain attached files and by making direct requests to obtain issue information. The
project issue access function is involved in this issue.Recommendations
For versions 4.7.0 through 5.x before 20070123, consider restricting access to the
project issue access function until a fix is available. Additionally, limiting direct requests to issue information and securing file attachments can help mitigate the risk.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Office Project