PT-2017-10996 · Tracker · Dtracker

Larry W. Cashdollar

+1

·

Published

2017-09-14

·

Updated

2019-10-03

·

CVE-2017-1002007

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions DTracker version 1.5
Description The issue concerns a lack of authorization check in the code, specifically in the dtracker/save mail.php file, which allows unauthorized injection of new contacts into the wp contact table.
Recommendations For DTracker version 1.5, consider temporarily restricting access to the dtracker/save mail.php file until a patch is available, and ensure that proper authorization checks are implemented to prevent unauthorized modifications to the wp contact table.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-1002007

Affected Products

Dtracker