PT-2022-8290 · Axios Italia · Axios Re

Erpaciocco

·

Published

2022-06-09

·

Updated

2022-06-16

·

CVE-2019-25068

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Axios Italia Axios RE versions 1.7.0 through 7.0.0
Description A critical issue was found in the Connection Handler component, specifically affecting the REDefault.aspx file. The manipulation of the DBIDX argument leads to privilege escalation. This issue can be exploited remotely.
Recommendations For versions 1.7.0 through 7.0.0, consider restricting access to the Connection Handler component to minimize the risk of exploitation. As a temporary workaround, avoid using the DBIDX argument in the affected component until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-25068

Affected Products

Axios Re