← Back

CVE-2018-16704

nvd nist
Published: Sep 7, 2018Modified: Nov 21, 2024

JSON object

Loading...
4.3
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

An issue was discovered in Gleez CMS v1.2.0. Because of an Insecure Direct Object Reference vulnerability, it is possible for attackers (logged in users) to view profile page of other users, as demonstrated by navigating to user/3 on demo.gleezcms.org.

Affected (1)

Products: Gleeztech: Gleezcms
1 product
Gleezcms
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.3.0

References (2)

Source: cve@mitre.org
MitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party Advisory

Timeline

No history available yet.