PT-2018-16897 · Zuuse · Zuuse Beims Contractorweb
Published
2018-01-15
·
Updated
2019-10-03
·
CVE-2018-5328
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ZUUSE BEIMS ContractorWeb .NET version 5.18.0.0
Description
The issue allows access to various privileged modules, such as "UserManagement", without properly authenticating the user. This can be exploited by an attacker to perform unauthorized actions, for example, by accessing the "Edit User Details" functionality.
Recommendations
For version 5.18.0.0, consider restricting access to the /UserManagement/ module until a proper authentication mechanism is implemented to prevent unauthorized actions. As a temporary workaround, restrict access to the "Edit User Details" functionality to minimize the risk of exploitation.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zuuse Beims Contractorweb