4 results (0.001 seconds)

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 1

An access control issue in Registration.aspx of Temenos CWX 8.5.6 allows authenticated attackers to escalate privileges and perform arbitrary Administrative commands. • http://cwx.com http://temenos.com https://github.com/WhiteBearVN/CWX-Registration-Broken-Access-Control/blob/main/README.md •

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 1

Broken access control in the Registration page (/Registration.aspx) of Termenos CWX v8.5.6 allows attackers to access sensitive information. Un control de acceso defectuoso en la página de registro (/Registration.aspx) de Termenos CWX v8.5.6 permite a los atacantes acceder a información confidencial. • https://github.com/WhiteBearVN/CWX-Registration-Broken-Access-Control • CWE-732: Incorrect Permission Assignment for Critical Resource •

CVSS: 7.5EPSS: 1%CPEs: 1EXPL: 1

An issue was discovered in T24 in TEMENOS Channels R15.01. The login page presents JavaScript functions to access a document on the server once successfully authenticated. However, an attacker can leverage downloadDocServer() to traverse the file system and access files or directories that are outside of the restricted directory because WealthT24/GetImage is used with the docDownloadPath and uploadLocation parameters. Se detectó un problema en T24 en TEMENOS Channels versión R15.01. La página de inicio de sesión presenta funciones de JavaScript para acceder a un documento en el servidor una vez autenticado con éxito. • https://github.com/kmkz/exploit/blob/master/CVE-2019-14251-TEMENOS-T24.txt • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 1

Temenos CWX version 8.9 has an Broken Access Control vulnerability in the module /CWX/Employee/EmployeeEdit2.aspx, leading to the viewing of user information. Temenos CWX versión 8.9 tiene una vulnerabilidad del Control de Acceso Roto en el módulo /CWX/Employee/EmployeeEdit2.aspx, que conlleva a la visualización de la información del usuario. • https://github.com/B3Bo1d/CVE-2019-13403 •