CVE Vulnerabilities

CVE-2021-34369

Published: Jun 09, 2021 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

portlets/contact/ref/refContactDetail.do in Accela Civic Platform through 20.1 allows remote attackers to obtain sensitive information via a modified contactSeqNumber value. NOTE: the vendor states the information that is being queried is authorized for an authenticated user of that application, so we consider this not applicable.

Affected Software

Name Vendor Start Version End Version
Civic_platform Accela * 20.1 (including)

References