Avolve Software ProjectDox 8.1 makes it easier for remote authenticated users to obtain sensitive information by leveraging ciphertext reuse.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/533345/100/0/threaded | mailing list vdb entry third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/95736 | vdb entry third party advisory |
http://packetstormsecurity.com/files/128157/ProjectDox-8.1-XSS-User-Enumeration-Ciphertext-Reuse.html | vdb entry third party advisory |
http://www.securityfocus.com/bid/69632 | vdb entry third party advisory |