PT-2021-9003 · Rock Rms · Rock Rms

Published

2021-01-07

·

Updated

2021-01-13

·

CVE-2019-18642

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Rock RMS versions prior to 8.6
Description The issue allows for account takeover by tampering with the user ID parameter in the profile update feature. This is possible due to the lack of validation and the use of sequential user IDs, enabling any user to change account details of any other user. An attacker could exploit this to change the email address of another account, including the administrator account, and then perform a password reset to the new email address to take over the account.
Recommendations For versions prior to 8.6, update to version 8.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the profile update feature to minimize the risk of exploitation. Additionally, avoid using the user ID parameter in the profile update feature until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2019-18642

Affected Products

Rock Rms