W Real Estate Management System 1.0 firmy ScriptAndTools odkryto podatność krytyczną w pliku userdelete.php komponentu User Delete Handler. Manipulacja parametrem ID umożliwia obejście autoryzacji, co pozwala na zdalne wykonanie ataku. Exploit został ujawniony publicznie.
▸ Pokaż oryginał (EN)
A vulnerability was found in ScriptAndTools Real Estate Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file userdelete.php of the component User Delete Handler. The manipulation of the argument ID leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XScriptandtools Real Estate Management System
APPScriptandtools1.0
Powiązane podatności
A security vulnerability has been detected in ScriptAndTools Real Estate Management System 1.0. The affected e...
A vulnerability, which was classified as critical, was found in ScriptAndTools Real-Estate-website-in-PHP 1.0....
Odkryta została podatność w ScriptAndTools Real Estate Management System 1.0. Podatność dotyczy nieznanej funk...
A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been classified as critical. Th...
A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been declared as critical. This...