HIGH · 7.5

CVE-2007-1923

(1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control lists by changing the set of URLs linked from menus, which allows remote attackers to access restricted functionality via direct r...

Vulnerability Description

(1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control lists by changing the set of URLs linked from menus, which allows remote attackers to access restricted functionality via direct requests. The LedgerSMB affected versions are before 1.3.0.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
LedgersmbLedgersmb< 1.3.0
Sql-LedgerSql-Ledger-

References

FAQ

What is CVE-2007-1923?

CVE-2007-1923 is a vulnerability with a CVSS score of 7.5 (HIGH). (1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control lists by changing the set of URLs linked from menus, which allows remote attackers to access restricted functionality via direct r...

How severe is CVE-2007-1923?

CVE-2007-1923 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-1923?

Check the references section above for vendor advisories and patch information. Affected products include: Ledgersmb Ledgersmb, Sql-Ledger Sql-Ledger.