In Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users profile information by manipulating the unvalidated UserIndex parameter, aka Insecure Direct Object Reference.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Egov | Newgensoft | 12.0 (including) | 12.0 (including) |