Vulnerability Description
NetCommons 2.4.2.1 and earlier allows remote authenticated secretariat (aka CLERK) users to gain privileges by creating a SYSTEM_ADMIN account.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netcommons | Netcommons | <= 2.4.2.1 |
Related Weaknesses (CWE)
References
- http://jvn.jp/en/jp/JVN00460236/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2016-000075Vendor Advisory
- http://www.netcommons.org/muer4mz6s-6669Vendor Advisory
- http://jvn.jp/en/jp/JVN00460236/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2016-000075Vendor Advisory
- http://www.netcommons.org/muer4mz6s-6669Vendor Advisory
FAQ
What is CVE-2016-4813?
CVE-2016-4813 is a vulnerability with a CVSS score of 8.8 (HIGH). NetCommons 2.4.2.1 and earlier allows remote authenticated secretariat (aka CLERK) users to gain privileges by creating a SYSTEM_ADMIN account.
How severe is CVE-2016-4813?
CVE-2016-4813 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-4813?
Check the references section above for vendor advisories and patch information. Affected products include: Netcommons Netcommons.