CVE-2021-34369
09.06.2021, 12:15
portlets/contact/ref/refContactDetail.do in Accela Civic Platform through 20.1 allows remote attackers to obtain sensitive information via a modified contactSeqNumber value. NOTE: the vendor states "the information that is being queried is authorized for an authenticated user of that application, so we consider this not applicable.Enginsight
Vendor | Product | Version |
---|---|---|
accela | civic_platform | 𝑥 ≤ 20.1 |
𝑥
= Vulnerable software versions
References