CVE-2016-4813

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
19/06/2016
Last modified:
12/04/2025

Description

NetCommons 2.4.2.1 and earlier allows remote authenticated secretariat (aka CLERK) users to gain privileges by creating a SYSTEM_ADMIN account.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:netcommons:netcommons:*:*:*:*:*:*:*:* 2.4.2.1 (including)