vendor:
Plastic SCM
by:
Basavaraj Banakar
7.5
CVSS
HIGH
Server Access
287
CWE
Product Name: Plastic SCM
Affected Version From: Plastic SCM < 10.0.16.5622
Affected Version To: Plastic SCM < 10.0.16.5622
Patch Exists: YES
Related CWE: CVE-2021-41382
CPE: a:plasticscm:plastic_scm
Platforms Tested: Chrome,Firefox,Edge
2021
Plastic SCM 10.0.16.5622 – WebAdmin Server Access
Navigate to target.com/account [This holds administrator login console], Change URL to target.com/account/register [Here able to set new password for the adminstrator user], Now after changing password of administrator and login to console and Navigate to target.com/configuration/authentication and set an new password for any of the users, Now navigate to target.com/webui/repos and login with the recently changed password for user i.e is in step 3, Now you have access to the webadmin server
Mitigation:
Ensure that the webadmin server is properly secured and access is restricted to authorized users only.