vendor:
Eventlog Analyzer
by:
@GraphX
7,5
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: Eventlog Analyzer
Affected Version From: 4.0
Affected Version To: 10
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020
ManageEngine Eventlog Analyzer Privilege Escalation
The manageengine eventlog analyzer fails to properly verify user privileges when making changes via the userManagementForm.do. An unprivileged user would be allowed to make changes to any account by changing the USER_ID field to a number corresponding to another user. Testing discovered that the default admin and guest accounts are 1 and 2.
Mitigation:
Upgrade to 10.8