Escalation of privileges in EnergyCAP 7 through 7.5.6 allows an attacker to access data. If an unauthenticated user clicks on a link on the public dashboard, the resource opens in EnergyCAP with access rights matching the user who created the dashboard.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T01:54:14.523Z

Reserved: 2019-10-29T00:00:00

Link: CVE-2019-18623

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-11-08T18:15:13.607

Modified: 2024-11-21T04:33:23.307

Link: CVE-2019-18623

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.