PT-2023-10630 · Instedd · Instedd Pollit
Published
2023-02-21
·
Updated
2024-05-17
·
CVE-2017-20179
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
InSTEDD Pollit version 2.3.1
Description
A critical issue affects the
TourController function of the file app/controllers/tour controller.rb. The manipulation leads to an unknown weakness, and the attack may be initiated remotely. Upgrading to version 2.3.2 addresses this issue.Recommendations
For InSTEDD Pollit version 2.3.1, upgrade to version 2.3.2 to address the issue. As a temporary workaround, consider disabling the
TourController function until the patch is applied.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Instedd Pollit