CVE Vulnerabilities

CVE-2021-34369

Published: Jun 09, 2021 | Modified: Apr 11, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

portlets/contact/ref/refContactDetail.do in Accela Civic Platform through 20.1 allows remote attackers to obtain sensitive information via a modified contactSeqNumber value. NOTE: the vendor states the information that is being queried is authorized for an authenticated user of that application, so we consider this not applicable.

Affected Software

Name Vendor Start Version End Version
Civic_platform Accela * 20.1 (including)

References