Privilege escalation in Cisco Prime Collaboration Provisioning - CVE-2018-0317
Published: June 7, 2018
Cisco Prime Collaboration Provisioning
Detailed vulnerability description
The vulnerability allows a remote authenticated attacker to gain elevated privileges on the target system.
The vulnerability exists in the web interface of Cisco Prime Collaboration Provisioning (PCP) due to insufficient web portal access control checks. A remote attacker can modify an access request, promote their account to any role defined on the system and gain elevated privileges.