CVE-2019-18626
25.03.2020, 18:15
Harris Ormed Self Service before 2019.1.4 allows an authenticated user to view W-2 forms belonging to other users via an arbitrary empNo value to the ORMEDMIS/Data/PY/T4W2Service.svc/RetrieveW2EntriesForEmployee URI, thus exposing sensitive information including employee tax information, social security numbers, home addresses, and more.Enginsight
Vendor | Product | Version |
---|---|---|
harriscomputer | ormed_mis | 𝑥 < 2019.1.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration