An Incorrect Access Control vulnerability in "/admin/benutzer/institution/rechteverwaltung/uebersicht" in Feripro <= v2.2.3 allows remote attackers to get a list of all users and their corresponding privileges.
Link | Tags |
---|---|
https://piuswalter.de/blog/multiple-vulnerabilities-in-feripro/ | third party advisory |
http://feripro.de | |
http://mecodia.de |