Vulnerability Description
An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, anyone can add a vendor account or read existing vendor account data (including usernames and passwords).
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Personifycorp | Personify360 | 7.5.2 |
Related Weaknesses (CWE)
References
- https://amswoes.wordpress.com/2017/06/06/first-blog-post/Third Party Advisory
- https://amswoes.wordpress.com/2017/06/06/first-blog-post/Third Party Advisory
FAQ
What is CVE-2017-7312?
CVE-2017-7312 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, anyone can add a vendor account or read existing vendor account data (including usernames and ...
How severe is CVE-2017-7312?
CVE-2017-7312 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-7312?
Check the references section above for vendor advisories and patch information. Affected products include: Personifycorp Personify360.