Vulnerability Description
Techno - Portfolio Management Panel through 2017-11-16 does not check authorization for panel/portfolio.php?action=delete requests that remove feedback.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Techno - Portfolio Management Panel Project | Techno - Portfolio Management Panel | <= 2017-11-16 |
Related Weaknesses (CWE)
References
- https://github.com/d4wner/Vulnerabilities-Report/blob/master/Techno-Portfolio-MaExploitThird Party Advisory
- https://github.com/d4wner/Vulnerabilities-Report/blob/master/Techno-Portfolio-MaExploitThird Party Advisory
FAQ
What is CVE-2017-17693?
CVE-2017-17693 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Techno - Portfolio Management Panel through 2017-11-16 does not check authorization for panel/portfolio.php?action=delete requests that remove feedback.
How severe is CVE-2017-17693?
CVE-2017-17693 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-17693?
Check the references section above for vendor advisories and patch information. Affected products include: Techno - Portfolio Management Panel Project Techno - Portfolio Management Panel.