Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Cristina Coppola

#43083of 56,330
6.5Total CVSS
Vulnerabilities · 1
PT-2024-13976
6.5
2024-03-19
Selesta · Selesta Visual Access Manager · CVE-2023-50811
**Name of the Vulnerable Software and Affected Versions** SELESTA Visual Access Manager version 4.38.6 **Description** An issue in SELESTA Visual Access Manager allows attackers to modify the `computer` POST parameter related to the ID of a specific reception by POST HTTP request interception. This can lead to unauthorized access to the application and control of many other receptions beyond the assigned one. The issue can be exploited via local network only. **Recommendations** For SELESTA Visual Access Manager version 4.38.6, restrict local network access and monitor logs until a patch is available. As a temporary workaround, consider restricting access to the `computer` POST parameter to minimize the risk of exploitation.