vendor:
Perspective ICM Investigation & Case
by:
Konstantinos.alexiou@hotmail.com
8,8
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: Perspective ICM Investigation & Case
Affected Version From: 5.1.1.16
Affected Version To: 5.1.1.16
Patch Exists: YES
Related CWE: CVE-2017-11319
CPE: a:resolver:perspective_icm_investigation_and_case:5.1.1.16
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 8.1
2017
Privilege Escalation – Perspective ICM Investigation & Case – 5.1.1.16
The CIS application permits tampering of users’ permission values which are loaded through the following methods inside the Perspective.data.dll just after the initial authentication phase and before the graphical users’ interface is loaded: accessLevels(), userEntityPrivs(), userFieldPrivs(). Due to insufficient validation methods and missing cross server side checking mechanisms, unprivileged authenticated users are allowed to modify their access level permissions by tampering and modifying these values thus gaining access to priveleged users actions.
Mitigation:
Implement proper validation and cross server side checking mechanisms to prevent unprivileged users from tampering with their access level permissions.