← Back

CVE-2019-16106

nvd nist
Published: Sep 10, 2019Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the password of any user via the recruitment_online/personalData/act_acounttab.cfm txtNewUserName and hdNP fields.

Affected (2)

Products: Humanica: Humatrix
1 product
Humatrix
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Humanica
Version 1.0.0.681
Version 7.1.0.0.203

Timeline

No history available yet.