vendor:
CONTENTCustomizer
by:
7.5
CVSS
HIGH
Unauthorized Access
22
CWE
Product Name: CONTENTCustomizer
Affected Version From: 3.1mp
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Unauthorized Access Vulnerability in CONTENTCustomizer
The application fails to sanitize user-supplied input, allowing an attacker to delete arbitrary files, rename files, or reset the content of certain files.
Mitigation:
Implement input validation and sanitization techniques to prevent unauthorized access.