Hosting Controller 6.1 Hotfix 2.1 allows remote authenticated users to perform unauthorized actions, such as modifying the credit limit, via a direct request to AccountActions.asp and modifying the CreditLimit parameter in an UpdateCreditLimit action.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Hosting_controller | Hosting_controller | 6.1_hotfix_2.1 (including) | 6.1_hotfix_2.1 (including) |