NA

CVE-2023-50811

Published: 19/03/2024 Updated: 29/04/2024
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8

Vulnerability Summary

An issue discovered in SELESTA Visual Access Manager 4.38.6 allows malicious users to modify the “computer” POST parameter related to the ID of a specific reception by POST HTTP request interception. Iterating that parameter, it has been possible to access to the application and take control of many other receptions in addition the assigned one.

Vulnerable Product Search on Vulmon Subscribe to Product

seling visual access manager 4.38.6