NA

CVE-2020-35675

Published: 29/09/2022 Updated: 03/10/2022
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

BigProf Online Invoicing System prior to 3.0 offers a functionality that allows an administrator to move the records of members across groups. The applicable endpoint (admin/pageTransferOwnership.php) lacks CSRF protection, resulting in an attacker being able to escalate their privileges to Administrator and effectively taking over the application.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

bigprof online invoicing system