PT-2015-6000 · Igreks · Milkystep Light+1

Kusano Kazuhiko

·

Published

2015-06-13

·

Updated

2016-12-03

·

CVE-2015-2952

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
The user-information management functionality in Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote authenticated users to bypass intended access restrictions and modify administrative credentials via unspecified vectors, a different vulnerability than CVE-2015-2953 and CVE-2015-2958.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-2952

Affected Products

Milkystep Light
Milkystep Professional