Exploitation Summary
EIP tracks 1 public exploit for CVE-2017-7314. PoCs published by Pesach Zirkind.
AI-analyzed exploit summary This exploit describes an information disclosure vulnerability in Personify software versions 7.5.2 to 7.6.1, allowing unauthenticated users to access database schema details via a specific URL path and UI interaction. The PoC outlines steps to reproduce the issue but does not include executable code.
Description
An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, while creating a new role, a list of database tables and their columns is available.
Exploits (1)
This exploit describes an information disclosure vulnerability in Personify software versions 7.5.2 to 7.6.1, allowing unauthenticated users to access database schema details via a specific URL path and UI interaction. The PoC outlines steps to reproduce the issue but does not include executable code.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N