vendor:
FileBound On-Site
by:
Nathaniel Carew
7,5
CVSS
HIGH
Privilege escalation
not provided
CWE
Product Name: FileBound On-Site
Affected Version From: All versions prior to 6.2
Affected Version To: All versions prior to 6.2
Patch Exists: YES
Related CWE: not yet assigned
CPE: not provided
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2012
Sense of Security – Security Advisory – SOS-12-010
The FileBound On-Site document management application is vulnerable to a privilege escalation attack by sending a modified password request to the FileBound web service. By modifying the UserID value you can reset the password of any local user in the application without requiring administrative privileges.
Mitigation:
Install the latest vendor patch.