PT-2018-6552 · Pleasant Solutions · Pleasant Password Server
Published
2018-07-31
·
Updated
2019-10-03
·
CVE-2017-17708
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Pleasant Password Server versions prior to 7.8.3
Description:
The issue is due to insufficient authorization checks, allowing any authenticated user to modify profile data of other users.
Recommendations:
For versions prior to 7.8.3, update to version 7.8.3 or later to resolve the issue.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pleasant Password Server