PT-2021-9003 · Rock Rms · Rock Rms
Published
2021-01-07
·
Updated
2021-01-13
·
CVE-2019-18642
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Rock RMS versions prior to 8.6
Description
The issue allows for account takeover by tampering with the
user ID parameter in the profile update feature. This is possible due to the lack of validation and the use of sequential user IDs, enabling any user to change account details of any other user. An attacker could exploit this to change the email address of another account, including the administrator account, and then perform a password reset to the new email address to take over the account.Recommendations
For versions prior to 8.6, update to version 8.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the profile update feature to minimize the risk of exploitation. Additionally, avoid using the
user ID parameter in the profile update feature until the issue is resolved.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rock Rms