Permissions, Privileges, and Access Controls in Password Manager Pro - #VU84523

 

Permissions, Privileges, and Access Controls in Password Manager Pro - #VU84523

Published: December 18, 2023


Vulnerability identifier: #VU84523
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges within the application.

The vulnerability exists due to improperly imposed security restrictions. A remote user can update other users' PGP keys, deploy unowned IIS binding info, delete certificate groups of other users.

Affected software

Password Manager Pro

Remediation

Install updates from vendor's website.

Password Manager Pro - update to 12330

External References

Related Security Bulletins