CVE-2016-15002

A vulnerability, which was classified as critical, was found in MONyog Ultimate 6.63. This affects an unknown part of the component Cookie Handler. The manipulation of the argument HasServerEdit/IsAdmin leads to privilege escalation. It is possible to initiate the attack remotely.
References
Link Resource
https://vuldb.com/?id.98355 Third Party Advisory
https://youtu.be/KKlwi-u6wyA Exploit Third Party Advisory
https://vuldb.com/?id.98355 Third Party Advisory
https://youtu.be/KKlwi-u6wyA Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:ideracorp:webyog_monyog_ultimate:6.63:*:*:*:*:*:*:*

History

21 Nov 2024, 02:45

Type Values Removed Values Added
CVSS v2 : 6.5
v3 : 8.8
v2 : 6.5
v3 : 7.3
References () https://vuldb.com/?id.98355 - Third Party Advisory () https://vuldb.com/?id.98355 - Third Party Advisory
References () https://youtu.be/KKlwi-u6wyA - Exploit, Third Party Advisory () https://youtu.be/KKlwi-u6wyA - Exploit, Third Party Advisory

Information

Published : 2022-06-09 17:15

Updated : 2024-11-21 02:45


NVD link : CVE-2016-15002

Mitre link : CVE-2016-15002

CVE.ORG link : CVE-2016-15002


JSON object : View

Products Affected

ideracorp

  • webyog_monyog_ultimate
CWE
CWE-269

Improper Privilege Management

CWE-565

Reliance on Cookies without Validation and Integrity Checking