CVE Vulnerabilities

CVE-2023-50811

Published: Mar 19, 2024 | Modified: Apr 29, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue discovered in SELESTA Visual Access Manager 4.38.6 allows attackers to modify the “computer” POST parameter related to the ID of a specific reception by POST HTTP request interception. Iterating that parameter, it has been possible to access to the application and take control of many other receptions in addition the assigned one.

Affected Software

Name Vendor Start Version End Version
Visual_access_manager Seling 4.38.6 (including) 4.38.6 (including)

References