CVE-2017-7312

CRITICAL

Personify360 e-Business <7.6.1 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-7312. PoCs published by Pesach Zirkind.

AI-analyzed exploit summary This exploit describes an authentication bypass vulnerability in Personify software versions 7.5.2 to 7.6.1, allowing unauthenticated access to vendor management pages where credentials can be viewed or modified. The PoC involves navigating to a specific URL and interacting with the vendor management interface.

Description

An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, anyone can add a vendor account or read existing vendor account data (including usernames and passwords).

Exploits (1)

exploitdb WRITEUP
by Pesach Zirkind · textwebappsaspx
https://www.exploit-db.com/exploits/41985

This exploit describes an authentication bypass vulnerability in Personify software versions 7.5.2 to 7.6.1, allowing unauthenticated access to vendor management pages where credentials can be viewed or modified. The PoC involves navigating to a specific URL and interacting with the vendor management interface.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Personify (versions 7.5.2 - 7.6.1)
No auth needed
Prerequisites: Access to the target web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://amswoes.wordpress.com/2017/06/06/first-blog-post/

Scores

CVSS v3 9.8
EPSS 0.0297
EPSS Percentile 85.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-269
Status published
Products (3)
personifycorp/personify360 7.5.2
personifycorp/personify360 7.6
personifycorp/personify360 7.6.1
Published Jun 07, 2017
Tracked Since Feb 18, 2026