Prototype 1.6.0.1 allows remote authenticated users to forge ticket creation (on behalf of other user accounts) via a modified email ID field.
References
Link | Resource |
---|---|
https://github.com/prototypejs/prototype/blob/master/CHANGELOG | Third Party Advisory |
https://medium.com/@vbharad/improper-access-control-vulnerability-in-prototype-1-6-0-1-framework-379cc3a05079 | Exploit Third Party Advisory |
Configurations
Information
Published : 2020-02-03 07:15
Updated : 2021-07-21 04:39
NVD link : CVE-2020-7993
Mitre link : CVE-2020-7993
JSON object : View
CWE
CWE-862
Missing Authorization
Products Affected
prototypejs
- prototype