PT-2018-6551 · Pleasant Solutions · Pleasant Password Server

Philipp Rocholl

·

Published

2018-07-31

·

Updated

2019-10-03

·

CVE-2017-17707

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Pleasant Password Server versions prior to 7.8.3
Description: The issue arises from missing authorization checks, allowing any authenticated user to list, upload, or delete attachments to password safe entries. To perform these actions, a user needs to know the corresponding CredentialId value, which is a GUID that uniquely identifies a password safe entry. Although CredentialId values are hard to guess, they can be exposed to malicious users if an entry's owner grants read-only access or temporary grants.
Recommendations: For versions prior to 7.8.3, update to version 7.8.3 or later to resolve the issue. As a temporary workaround, consider restricting access to password safe entries and avoiding granting read-only access or temporary grants to untrusted users. Additionally, limit the exposure of CredentialId values to minimize the risk of exploitation.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-17707

Affected Products

Pleasant Password Server