CVE-2020-25917
Severity CVSS v4.0:
Pending analysis
Type:
CWE-669
Incorrect Resource Transfer Between Spheres
Publication date:
26/12/2020
Last modified:
21/07/2021
Description
Stratodesk NoTouch Center before 4.4.68 is affected by: Incorrect Access Control. A low privileged user on the platform, for example a user with "helpdesk" privileges, can perform privileged operations including adding a new administrator to the platform via the easyadmin/user/submitCreateTCUser.do page.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
6.50
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:stratodesk:notouch_center:*:*:*:*:*:*:*:* | 4.4.68 (excluding) |
To consult the complete list of CPE names with products and versions, see this page