QPR Portal before 2012.2.1 allows remote attackers to modify or delete notes via a direct request.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.kb.cert.org/vuls/id/546340 | us government resource third party advisory patch |