PT-2007-3914 · Rsa · Rsauction
Published
2007-05-11
·
Updated
2017-07-29
·
CVE-2007-2595
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
RSAuction version 2.73.1.3
Description
The issue allows remote authenticated users to change their account status from Suspended to Active by directly requesting the activation URL provided during account registration.
Recommendations
For RSAuction version 2.73.1.3, consider restricting access to the account activation URL to prevent unauthorized account status changes until a proper fix is applied.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rsauction