Description
Authentication Bypass vulnerability in Accellion kiteworks before 2017.01.00 allows remote attackers to execute certain API calls on behalf of a web user using a gathered token via a POST request to /oauth/token.
References (1)
Core 1
Core References
Third Party Advisory x_refsource_misc
https://github.com/jer1nj0y/Vulns/blob/master/Kiteworks%20Vulnerability
Scores
CVSS v3
6.5
EPSS
0.0106
EPSS Percentile
60.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Details
CWE
CWE-287
Status
published
Products (1)
accellion/kiteworks
< 2017.01.00
Published
May 24, 2018
Tracked Since
Feb 18, 2026