CVE-2022-27960
10.04.2022, 21:15
Insecure permissions configured in the user_id parameter at SysUserController.java of OFCMS v1.1.4 allows attackers to access and arbitrarily modify users' personal information.Enginsight
Vendor | Product | Version |
---|---|---|
ofcms_project | ofcms | 1.1.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration