The e-School from Ventem has a Missing Authorization vulnerability, allowing remote attackers with regular privilege to access administrator functions, including creating, modifying, and deleting accounts. They can even escalate any account to system administrator privilege.
Solution:
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://www.twcert.org.tw/tw/cp-132-10304-6b375-1.html | third party advisory |
https://www.twcert.org.tw/en/cp-139-10305-2eca0-2.html | third party advisory |