PT-2009-1584 · Robin Rawson Tetley · Robin Rawson-Tetley Animal Shelter Manager

Published

2009-02-11

·

Updated

2017-08-08

·

CVE-2008-6109

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Robin Rawson-Tetley Animal Shelter Manager (ASM) versions prior to 2.2.2
Description The issue concerns improper enforcement of user account privileges, allowing local users to bypass access restrictions. This can be achieved by opening unspecified screens, related to the "double click selector bug", or by modifying specific records, including animal, owner, lost/found, diary note, owner donation, or waiting list records, related to "change permissions" and the "new UI".
Recommendations For versions prior to 2.2.2, update to version 2.2.2 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive screens and records to minimize the risk of exploitation. Avoid using the "change permissions" feature in the new UI until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-6109

Affected Products

Robin Rawson-Tetley Animal Shelter Manager