vendor:
Filemaker Pro
by:
Giuseppe D'Amore
7,2
CVSS
HIGH
Authentication Bypass and Privilege Escalation
N/A
CWE
Product Name: Filemaker Pro
Affected Version From: FileMaker Pro 13.0v3
Affected Version To: FileMaker Pro Advanced 12.0v4
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Desktop Application
2014
Filemaker Login Bypass and Privilege Escalation
There is a obvious vulnerability of FileMaker that allow access to the local FM-based database file: On DBEngine dll, there is a function called MatchPasswordData: it doesn't matter if your desktop or mobile application is developed in a "secure manner", your confidential data on the database can be accessed.
Mitigation:
Upgrade to the latest version of FileMaker Pro 13.0v3 - FileMaker Pro Advanced 12.0v4