Record summary

CVE-2018-1322 has a selected CVSS score of 4.9 (medium); EIP currently links 1 catalogued exploit.

Description

An administrator with user search entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can recover sensitive security values using the fiql and orderby parameters.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE ListReleases prior to 1.2.11, Releases prior to 2.0.8affected
The unsupported Releases 1.0.x, 1.1.x may be also affected.affected

org.apache.syncope:syncope-core

Browse Maven / org.apache.syncope:syncope-core
GitHub AdvisoryBefore 1.2.11 · Fixed in 1.2.11affected
2.0.0 to < 2.0.8 · Fixed in 2.0.8affected

Proofs of concept

1

Catalogued exploits

ExploitDBApache Syncope 2.0.7 - Remote Code ExecutionExploitDB exploitby Che-Chun KuoNot analyzed1 file

linked to 2 vulnerabilities

ExploitDB

PoC details

References

8