PT-2007-2670 · C1 Financial Services · C1 Financial Services Contelligent
Published
2007-03-03
·
Updated
2017-07-29
·
CVE-2007-1249
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
C1 Financial Services Contelligent version 9.1.4
Description
The issue concerns the MoveSortedContentAction in C1 Financial Services Contelligent, which fails to check the additional environment security configuration. This oversight allows remote attackers with write permissions to reorder components.
Recommendations
For version 9.1.4, consider restricting write permissions to prevent unauthorized component reordering until a patch is available. As a temporary workaround, review and monitor environment security configurations closely to minimize the risk of exploitation.
Fix
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
C1 Financial Services Contelligent