PT-2022-27067 · Unknown · Backclick Professional
Jannik Vieten
·
Published
2022-11-16
·
Updated
2025-04-30
·
CVE-2022-44005
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
BACKCLICK Professional version 5.9.63
Description
An issue was discovered in the newsletter sign-up functionality due to the use of consecutive IDs in verification links. This allows for the enumeration of subscribers' e-mail addresses. Furthermore, it is possible to subscribe and verify other persons' e-mail addresses to newsletters without their consent.
Recommendations
For version 5.9.63, consider implementing random or non-sequential IDs in verification links to prevent enumeration of subscribers' e-mail addresses. Additionally, restrict the ability to subscribe and verify e-mail addresses to prevent unauthorized access. As a temporary workaround, consider disabling the newsletter sign-up functionality until a patch is available.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Backclick Professional