An issue was discovered in RWS WorldServer before 11.7.3. Regular users can create users with the Administrator role via UserWSUserManager.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://www.rws.com/localization/products/trados-enterprise/worldserver/ | product |
https://www.triskelelabs.com/vulnerabilities-in-rws-worldserver | third party advisory exploit |