PT-2026-21798 · Unknown · Eventsentry
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
EventSentry versions prior to 6.0.1.20
Description
EventSentry has a flaw where passwords can be changed without verifying the current password through the account management functionality within the Web Reports interface. An attacker gaining access to an authenticated user session can modify the account password without knowing the original credentials. This allows for persistent account takeover, potentially leading to privilege escalation if administrative accounts are compromised.
Recommendations
Update EventSentry to version 6.0.1.20 or later.
Correção
LPE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Eventsentry