5
CVSSv2

CVE-2020-15958

Published: 18/09/2020 Updated: 21/07/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 8.6 | Impact Score: 4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

An issue exists in 1CRM System up to and including 8.6.7. An insecure direct object reference to internally stored files allows a remote malicious user to access various sensitive information via an unauthenticated request with a predictable URL.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

1crm 1crm

Exploits

1CRM versions 867 and below suffer from an insecure direct object reference vulnerability ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> ARA-2020-005: Insecure Direct Object Reference in 1CRM (CVE-2020-15958) <!--X-Subject-Header-End--> <!--X-Head-of-Mess ...