Vulnerabilities (CVE)

Filtered by vendor Alstrasoft Subscribe
Filtered by product Live Support
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2007-2775 1 Alstrasoft 1 Live Support 2024-11-21 10.0 HIGH N/A
AlstraSoft Live Support 1.21 sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to obtain administrative access via a direct request to admin/managesettings.php.