vendor:
Analog FM Transmitter
by:
LiquidWorm
7.5
CVSS
HIGH
Improper Access Control
287
CWE
Product Name: Analog FM Transmitter
Affected Version From: 2.12 (EXC5000GX)
Affected Version To: 1.5.4 (EXC120GT)
Patch Exists: NO
Related CWE:
CPE: a:sielco_s.r.l:analog_fm_transmitter
Platforms Tested: lwIP/2.1.1, Web/3.0.3
2023
Sielco Analog FM Transmitter 2.12 – Improper Access Control Change Admin Password
The application suffers from improper access control when editing users. A user with Read permissions can manipulate users, passwords and permissions by sending a single HTTP POST request with modified parameters and edit other users' names, passwords and permissions including admin password.
Mitigation:
Ensure that access control is properly implemented and enforced.