An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, anyone can add a vendor account or read existing vendor account data (including usernames and passwords).
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Personify360 | Personifycorp | 7.5.2 (including) | 7.5.2 (including) |
Personify360 | Personifycorp | 7.6 (including) | 7.6 (including) |
Personify360 | Personifycorp | 7.6.1 (including) | 7.6.1 (including) |