vendor:
Sonlogger Log and Report System
by:
Berkan Er
7.5
CVSS
HIGH
Remote SuperAdmin Account Creation Vulnerability / Information Disclosure
264
CWE
Product Name: Sonlogger Log and Report System
Affected Version From: 4.2.3.3
Affected Version To: 4.2.3.3
Patch Exists: YES
Related CWE: N/A
CPE: a:sonlogger:sonlogger_log_and_report_system
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 Enterprise x64 Version 1803
2021
Sonlogger 4.2.3.3 – SuperAdmin Account Creation / Information Disclosure
A remote attacker can be create an user with SuperAdmin profile by exploiting the vulnerability in Sonlogger Log and Report System - v4.2.3.3.
Mitigation:
Upgrade to the latest version of Sonlogger Log and Report System.