Insecure Permissions Vulnerability in TMS v2.28.0 Allows Unauthorized Modification of Administrator Account

Insecure Permissions Vulnerability in TMS v2.28.0 Allows Unauthorized Modification of Administrator Account

CVE-2022-26247 · MEDIUM Severity

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

TMS v2.28.0 contains an insecure permissions vulnerability via the component /TMS/admin/user/Update2. This vulnerability allows attackers to modify the administrator account and password.

Learn more about our User Device Pen Test.