ICS/StaticPages/AddTestUsers.aspx in Jenzabar JICS (aka Internet Campus Solution) before 2019-02-06 allows remote attackers to create an arbitrary number of accounts with a password of 1234.
References
Link | Resource |
---|---|
https://medium.com/@mdavis332/higher-ed-erp-portal-vulnerability-create-your-own-accounts-d865bd22cdd8 | Exploit Third Party Advisory |
Configurations
Information
Published : 2019-03-25 12:29
Updated : 2019-04-08 05:11
NVD link : CVE-2019-10011
Mitre link : CVE-2019-10011
JSON object : View
CWE
CWE-798
Use of Hard-coded Credentials
Products Affected
jenzabar
- internet_campus_solution