CVE-2019-17605

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
07/11/2019
Last modified:
24/08/2020

Description

A mass assignment vulnerability in eyecomms eyeCMS through 2019-10-15 allows any candidate to take over another candidate's account (by also exploiting CVE-2019-17604) via a modified candidate id and an additional password parameter. The outcome is that the password of this other candidate is changed.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:eyecomms:eyecms:*:*:*:*:*:*:*:* 2019-10-15 (including)