Описание
(1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control lists by changing the set of URLs linked from menus, which allows remote attackers to access restricted functionality via direct requests. The LedgerSMB affected versions are before 1.3.0.
Релиз | Статус | Примечание |
---|---|---|
artful | DNE | |
bionic | DNE | |
cosmic | DNE | |
dapper | ignored | end of life |
devel | DNE | |
disco | DNE | |
edgy | ignored | end of life, was needed |
eoan | DNE | |
esm-apps/xenial | needed | |
esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was needed] |
Показывать по
Ссылки на источники
7.5 High
CVSS2
Связанные уязвимости
(1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control lists by changing the set of URLs linked from menus, which allows remote attackers to access restricted functionality via direct requests. The LedgerSMB affected versions are before 1.3.0.
1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control ...
(1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control lists by changing the set of URLs linked from menus, which allows remote attackers to access restricted functionality via direct requests.
7.5 High
CVSS2