ZeroHour

CVE-2018-16606

PoC ×2
CVSS 3.0
6.5 medium
EPSS
6%p93
Published
()
Modified
Description

In ProConf before 6.1, an Insecure Direct Object Reference (IDOR) allows any author to view and grab all submitted papers (Title and Abstract) and their authors' personal information (Name, Email, Organization, and Position) by changing the value of Paper ID (the pid parameter).

Vendors
proconf
Products
proconf
Weakness
CWE-639
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.