5
CVSSv2

CVE-2016-6342

Published: 27/06/2017 Updated: 13/02/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

elog 3.1.1 allows remote malicious users to post data as any username in the logbook.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fedoraproject fedora 24

elog project elog 3.1.1

Vendor Advisories

Debian Bug report logs - #836505 elog: CVE-2016-6342: posting entry as arbitrary username by improper authentication Package: src:elog; Maintainer for src:elog is Roger Kalt <rogerkalt@gmailcom>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 3 Sep 2016 14:54:02 UTC Severity: grave Tags: patch, s ...