PT-2023-15885 · Unknown · Evolution Events Artaxerxes
Published
2023-01-05
·
Updated
2024-05-17
·
CVE-2022-4869
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Evolution Events Artaxerxes (affected versions not specified)
Description
A vulnerability was found in the component POST Parameter Handler, affecting unknown code of the file arta/common/middleware.py. The manipulation of the
password argument leads to information disclosure. The attack can be initiated remotely.Recommendations
To fix this issue, it is recommended to apply a patch. The patch is identified as 022111407d34815c16c6eada2de69ca34084dc0d. As a temporary workaround, consider restricting access to the vulnerable component POST Parameter Handler until a patch is available. Avoid using the
password argument in the affected middleware.py file until the issue is resolved.Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Evolution Events Artaxerxes