vendor:
Clonos WEB UI
by:
İbrahim Hakan Şeker
9.8
CVSS
CRITICAL
Improper Access Control
287
CWE
Product Name: Clonos WEB UI
Affected Version From: 19.09
Affected Version To: 19.09
Patch Exists: NO
Related CWE: CVE-2019-18418
CPE: a:clonos:clonos_web_ui
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: ClonOs
2019
ClonOs WEB UI 19.09 – Improper Access Control
ClonOs WEB UI 19.09 is vulnerable to improper access control. An attacker can exploit this vulnerability to gain access to the user accounts and change the passwords of the users.
Mitigation:
Ensure that proper access control is implemented and that users are authenticated before they are allowed to access the system.