PT-2020-7226 · Unknown · Arial Campaign Enterprise

Catatonic

·

Published

2020-01-10

·

Updated

2020-01-15

·

CVE-2012-3822

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Arial Campaign Enterprise versions prior to 11.0.551
Description The issue allows remote attackers to enumerate users' credentials due to unauthorized access to the User-Edit.asp page.
Recommendations For versions prior to 11.0.551, update to version 11.0.551 or later to resolve the issue. As a temporary workaround, consider restricting access to the User-Edit.asp page until the update is applied.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-3822

Affected Products

Arial Campaign Enterprise