CVE-2017-7313
07.06.2017, 13:29
An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, it is possible to read any customer name, master Customer Id, and email address. In other words, anyone can search for users/customers in the system - no authentication is required.Enginsight
Vendor | Product | Version |
---|---|---|
personify | personify360_e-business | 𝑥 ≤ 7.6.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration