An Incorrect Access Control vulnerability in "/admin/programm/<program_id>/export/statistics" in Feripro <= v2.2.3 allows remote attackers to export an XLSX file with information about registrations and participants.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://piuswalter.de/blog/multiple-vulnerabilities-in-feripro/ | third party advisory |
http://feripro.de | |
http://mecodia.de |