7.5
CVSSv3

CVE-2017-7314

Published: 07/06/2017 Updated: 14/06/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

An issue exists in Personify360 e-Business 7.5.2 up to and including 7.6.1. When going to the /TabId/275 URI, while creating a new role, a list of database tables and their columns is available.

Vulnerable Product Search on Vulmon Subscribe to Product

personify personify360 e-business

Exploits

# Exploit Title: Discover all tables and columns in database when creating new customer role # Date: 3/29/2017 # Exploit Author: Pesach Zirkind # Vendor Homepage: personifycorpcom/ # Version: 752 - 761 # Tested on: Windows (all versions) # CVE : CVE-2017-7314 # Category: webapps 1 Description Any website visitor can access a pag ...