CVE-2018-16606
PoC ×2—CVSS 3.0
6.5 medium
EPSS
6%p93
Published
()
Modified
Description
In ProConf before 6.1, an Insecure Direct Object Reference (IDOR) allows any author to view and grab all submitted papers (Title and Abstract) and their authors' personal information (Name, Email, Organization, and Position) by changing the value of Paper ID (the pid parameter).
- Vendors
- proconf
- Products
- proconf
- Weakness
- CWE-639
- Vector
- CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.