PT-2023-10630 · Instedd · Instedd Pollit

Published

2023-02-21

·

Updated

2024-05-17

·

CVE-2017-20179

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions InSTEDD Pollit version 2.3.1
Description A critical issue affects the TourController function of the file app/controllers/tour controller.rb. The manipulation leads to an unknown weakness, and the attack may be initiated remotely. Upgrading to version 2.3.2 addresses this issue.
Recommendations For InSTEDD Pollit version 2.3.1, upgrade to version 2.3.2 to address the issue. As a temporary workaround, consider disabling the TourController function until the patch is applied.

Fix

Related Identifiers

CVE-2017-20179

Affected Products

Instedd Pollit