In Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users profile information by manipulating the unvalidated UserIndex parameter, aka Insecure Direct Object Reference.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Egov | Newgensoft | 12.0 (including) | 12.0 (including) |