B3Bo1d / CVE-2019-13403

CVE-2019-13403

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

CVE-2019-13403

  • Report: May 2019
  • Fix: May 2019
  • Credit: B3Bo1d

Description

Temenos CWX version 8.9 has an Broken Access Control vulnerability in the module /CWX/Employee/EmployeeEdit2.aspx, leading to the viewing of user information.

PoC

Before Alt text After Alt text

Reference

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13403

About

CVE-2019-13403