PT-2022-7845 · Unknown · Monyog Ultimate

Mulail Mohamed

·

Published

2022-06-09

·

Updated

2022-06-15

·

CVE-2016-15002

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MONyog Ultimate version 6.63
Description A critical issue was discovered, affecting the Cookie Handler component. The manipulation of the HasServerEdit/IsAdmin argument can lead to privilege escalation. This issue can be exploited remotely.
Recommendations For MONyog Ultimate version 6.63, consider restricting access to the Cookie Handler component until a patch is available. As a temporary workaround, avoid using the HasServerEdit/IsAdmin argument in sensitive operations to minimize the risk of exploitation.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-15002

Affected Products

Monyog Ultimate