vendor:
Achievo
by:
Pablo G. Milano
4
CVSS
MEDIUM
Authorization Flaw
N/A
CWE
Product Name: Achievo
Affected Version From: Achievo 1.4.3
Affected Version To: Achievo 1.4.3
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Any
2010
Multiple Authorization Flaws in Achievo 1.4.3
It is possible to create and delete arbitrary activities to and from arbitrary users by modifying IDs in client requests.
Mitigation:
Upgrade to version 1.4.5