Authentication Bypass Vulnerability in Igreks MilkyStep Light and Professional

Authentication Bypass Vulnerability in Igreks MilkyStep Light and Professional

CVE-2015-2952 · MEDIUM Severity

AV:N/AC:L/AU:S/C:P/I:P/A:P

The user-information management functionality in Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote authenticated users to bypass intended access restrictions and modify administrative credentials via unspecified vectors, a different vulnerability than CVE-2015-2953 and CVE-2015-2958.

Learn more about our User Device Pen Test.