CVE-2017-6513

Severity CVSS v4.0:
Pending analysis
Type:
CWE-275 Permission Issues
Publication date:
11/03/2017
Last modified:
20/04/2025

Description

The WHMCS Reseller Module V2 2.0.2 in Softaculous Virtualizor before 2.9.1.0 does not verify the user correctly, which allows remote authenticated users to control other virtual machines managed by Virtualizor by accessing a modified URL.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:softaculous:whmcs_reseller_module:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:softaculous:virtualizor:*:*:*:*:*:*:*:* 2.9.0.6 (including)