CVE-2018-13791
09.07.2018, 21:29
The HTTP API in ABBYY FlexiCapture before 12 Release 1 Update 7 allows an attacker to conduct Access Control attacks via the /FlexiCapture12/Login/Server/SevaUserProfile FlexiCaptureTmsSts2 parameter.Enginsight
Vendor | Product | Version |
---|---|---|
abbyy | flexicapture | 12.0.1.263 |
abbyy | flexicapture | 12.0.1.267 |
abbyy | flexicapture | 12.0.1.282 |
abbyy | flexicapture | 12.0.1.292 |
abbyy | flexicapture | 12.0.1.367 |
abbyy | flexicapture | 12.0.1.428 |
abbyy | flexicapture | 12.0.1.475 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration