PT-2022-15900 · Priority · Priority Web+1
Published
2022-07-06
·
Updated
2022-07-14
·
CVE-2022-23173
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
No specific software or versions are mentioned in the provided descriptions.
Description
This issue affects users who are not allowed to access certain functionality via the web interface. An attacker must first access the "Login menu - demo site" to view all application functionalities. Although the attacker will be notified that they are not authorized to access certain links due to the need for login credentials, after logging in, they can still access restricted functionalities by changing the value of the
prog step parameter from 0 to 1 or more.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Priority Web
Priority