Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote unauthenticated malicious users to bypass the login page, access sensitive information, and reset user passwords via URL modification.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
avaya scopia_pathfinder_10_pts_firmware 8.3.7.0.4 |
||
avaya scopia_pathfinder_20_pts_firmware 8.3.7.0.4 |