dotProject before 2.1 does not properly check privileges when invoking the Companies module, which allows remote attackers to access this module via a crafted URL. NOTE: some of these details are obtained from third party information.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/26080 | vdb entry |
http://secunia.com/advisories/27191 | patch vendor advisory third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/37202 | vdb entry |
http://bugs.dotproject.net/view.php?id=1910 | |
http://docs.dotproject.net/index.php/Closed_Issues_/_Feature_Requests_-_2.1 | patch |