ZeroHour

CVE-2017-7313

PoC
CVSS 3.0
7.5 high
EPSS
1%p68
Published
()
Modified
Description

An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, it is possible to read any customer name, master Customer Id, and email address. In other words, anyone can search for users/customers in the system - no authentication is required.

Vendors
personify
Products
personify360 e-business
Weakness
CWE-200
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.