9.8
CVSSv3

CVE-2019-18642

Published: 07/01/2021 Updated: 13/01/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Rock RMS version prior to 8.6 is vulnerable to account takeover by tampering with the user ID parameter in the profile update feature. The lack of validation and use of sequential user IDs allows any user to change account details of any other user. This vulnerability could be used to change the email address of another account, even the administrator account. Upon changing another account's email address, performing a password reset to the new email address could allow an malicious user to take over any account.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sparkdevnetwork rock rms

Exploits

Rock RMS suffers from arbitrary file upload, account takeover, and personal information disclosure vulnerabilities Various versions are affected ...