The HTTP API in ABBYY FlexiCapture before 12 Release 1 Update 7 allows an attacker to conduct Access Control attacks via the /FlexiCapture12/Login/Server/SevaUserProfile FlexiCaptureTmsSts2 parameter.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Flexicapture | Abbyy | 12.0.1.263 (including) | 12.0.1.263 (including) |
Flexicapture | Abbyy | 12.0.1.267 (including) | 12.0.1.267 (including) |
Flexicapture | Abbyy | 12.0.1.282 (including) | 12.0.1.282 (including) |
Flexicapture | Abbyy | 12.0.1.292 (including) | 12.0.1.292 (including) |
Flexicapture | Abbyy | 12.0.1.367 (including) | 12.0.1.367 (including) |
Flexicapture | Abbyy | 12.0.1.428 (including) | 12.0.1.428 (including) |
Flexicapture | Abbyy | 12.0.1.475 (including) | 12.0.1.475 (including) |