PT-2007-3914 · Rsa · Rsauction

Published

2007-05-11

·

Updated

2017-07-29

·

CVE-2007-2595

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions RSAuction version 2.73.1.3
Description The issue allows remote authenticated users to change their account status from Suspended to Active by directly requesting the activation URL provided during account registration.
Recommendations For RSAuction version 2.73.1.3, consider restricting access to the account activation URL to prevent unauthorized account status changes until a proper fix is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-2595

Affected Products

Rsauction