EIQ-2019-0039
ID |
EIQ-2019-0039 |
CVE |
- |
Description |
A signed-in user could bypass password prompt before editing platform user details |
Date |
24 Dec 2019 |
Severity |
1 - LOW |
CVSSv3 score |
CVSSv3 score not available on NIST NVD. |
Status |
|
Assessment |
A signed-in platform user could modify API request raw data to alter user profile details. When editing user details, the platform prompts for a user password only at GUI level. A signed-in user with at least the modify users permission, without admin access rights, and with a valid user token could modify the details of the user profile the token refers to by editing the API request raw data, and then by sending the updated request to the platform. Up to release 2.6.0 included, the platform enforces user password check for high-risk operations at GUI level. It does not enforce it also at API level. |
Mitigation |
Upgrade to EclecticIQ Platform 2.7.0 or later. |
Affected versions |
2.6.0 and earlier. |
Notes |
- |
< Back to all security issues and mitigation actions
In release notes 2.7.0