CVE Vulnerabilities

CVE-2017-6513

Published: Mar 11, 2017 | Modified: Apr 13, 2017
CVSS 3.x
9.9
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The WHMCS Reseller Module V2 2.0.2 in Softaculous Virtualizor before 2.9.1.0 does not verify the user correctly, which allows remote authenticated users to control other virtual machines managed by Virtualizor by accessing a modified URL.

Affected Software

Name Vendor Start Version End Version
Whmcs_reseller_module Softaculous 2.0.2 (including) 2.0.2 (including)

References