ZeroHour

CVE-2017-16631

CVSS 3.1
6.5 medium
EPSS
<1%p49
Published
()
Modified
Description

In SapphireIMS 4097_1, a guest user is able to change the password of an administrative user by utilizing an Insecure Direct Object Reference (IDOR) in the "Account Password Reset" functionality.

Vendors
sapphireims
Products
sapphireims
Weakness
CWE-732
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.