An issue was discovered in iPortalis iCS 7.1.13.0. An attacker can gain privileges by intercepting a request and changing UserRoleKey=COMPANY_ADMIN to UserRoleKey=DOMAIN_ADMIN (to achieve Domain Administrator access).
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2021-09-01T10:45:57
Updated: 2024-08-04T10:19:19.778Z
Reserved: 2020-02-16T00:00:00
Link: CVE-2020-9002
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-09-01T11:15:07.817
Modified: 2024-11-21T05:39:48.583
Link: CVE-2020-9002
Redhat
No data.