Exploitation Summary
EIP tracks 1 public exploit for CVE-2017-7312. PoCs published by Pesach Zirkind.
AI-analyzed exploit summary This exploit describes an authentication bypass vulnerability in Personify software versions 7.5.2 to 7.6.1, allowing unauthenticated access to vendor management pages where credentials can be viewed or modified. The PoC involves navigating to a specific URL and interacting with the vendor management interface.
Description
An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, anyone can add a vendor account or read existing vendor account data (including usernames and passwords).
Exploits (1)
This exploit describes an authentication bypass vulnerability in Personify software versions 7.5.2 to 7.6.1, allowing unauthenticated access to vendor management pages where credentials can be viewed or modified. The PoC involves navigating to a specific URL and interacting with the vendor management interface.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H