Permissions, Privileges, and Access Controls in Password Manager Pro - #VU84524
Published: December 18, 2023
Vulnerability identifier: #VU84524
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to alter information within the application.
The vulnerability exists due to application does not properly impose security restrictions. A remote administrator can add accounts to unshared resources and modify the entire attributes of unshared resource groups.
Affected software
Password Manager Pro
Remediation
Install updates from vendor's website.
Password Manager Pro - update to 12340