The Web interface of Evolution Controller Versions 2.04...
High severity
Unreviewed
Published
Apr 15, 2024
to the GitHub Advisory Database
•
Updated Apr 15, 2024
Description
Published by the National Vulnerability Database
Apr 15, 2024
Published to the GitHub Advisory Database
Apr 15, 2024
Last updated
Apr 15, 2024
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_CARD, allowing for an unauthenticated attacker to return the card value data of any user
References