Permissions, Privileges, and Access Controls in femanager direct mail subscription - #VU23659
Published: December 18, 2019
Vulnerability identifier: #VU23659
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to the affected software fails to properly check access rights. A remote authenticated attacker can escalate privileges on the target system and modify other frontend user records.Affected software
femanager direct mail subscription
Remediation
Install updates from vendor's website.
femanager direct mail subscription - update to 2.1.3