9.8
CVSSv3

CVE-2018-13791

Published: 09/07/2018 Updated: 03/10/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The HTTP API in ABBYY FlexiCapture prior to 12 Release 1 Update 7 allows an malicious user to conduct Access Control attacks via the /FlexiCapture12/Login/Server/SevaUserProfile FlexiCaptureTmsSts2 parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

abbyy flexicapture 12.0.1.475

abbyy flexicapture 12.0.1.428

abbyy flexicapture 12.0.1.367

abbyy flexicapture 12.0.1.292

abbyy flexicapture 12.0.1.267

abbyy flexicapture 12.0.1.282

abbyy flexicapture 12.0.1.263