CVE-2017-7312

CRITICAL

Personify360 e-Business <7.6.1 - Info Disclosure

Title source: llm

Description

An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, anyone can add a vendor account or read existing vendor account data (including usernames and passwords).

Exploits (1)

exploitdb WRITEUP
by Pesach Zirkind · textwebappsaspx
https://www.exploit-db.com/exploits/41985

Scores

CVSS v3 9.8
EPSS 0.0833
EPSS Percentile 92.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-269
Status published
Products (3)
personifycorp/personify360 7.5.2
personifycorp/personify360 7.6
personifycorp/personify360 7.6.1
Published Jun 07, 2017
Tracked Since Feb 18, 2026