9.8
CVSSv3

CVE-2017-7312

Published: 07/06/2017 Updated: 13/05/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in Personify360 e-Business 7.5.2 up to and including 7.6.1. When going to the /TabId/275 URI, anyone can add a vendor account or read existing vendor account data (including usernames and passwords).

Vulnerable Product Search on Vulmon Subscribe to Product

personifycorp personify360 7.5.2

personifycorp personify360 7.6

personifycorp personify360 7.6.1

Exploits

# Exploit Title: Access and read and create vendor / API credentials in plaintext # Date: 3/29/2017 # Exploit Author: Pesach Zirkind # Vendor Homepage: personifycorpcom/ # Version: 752 - 761 # Tested on: Windows (all versions) # CVE : CVE-2017-7312 # Category: webapps 1 Description Any website visitor can access a page that allo ...