An issue was discovered in Servisnet Tessa 0.0.2. Authorization data is available via an unauthenticated /data-service/users/ request.
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Link | Tags |
---|---|
http://www.servisnet.com.tr/en/page/products | product |
https://www.pentest.com.tr/exploits/Servisnet-Tessa-Privilege-Escalation.html | third party advisory exploit |
http://packetstormsecurity.com/files/165873/Servisnet-Tessa-Privilege-Escalation.html | exploit vdb entry third party advisory |
https://www.exploit-db.com/exploits/50712 | exploit vdb entry third party advisory |