CVE-2019-18623

CRITICAL

EnergyCAP <7.5.6 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Escalation of privileges in EnergyCAP 7 through 7.5.6 allows an attacker to access data. If an unauthenticated user clicks on a link on the public dashboard, the resource opens in EnergyCAP with access rights matching the user who created the dashboard.

Scores

CVSS v3 9.8
EPSS 0.0148
EPSS Percentile 70.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-269
Status published
Products (1)
energycap/energycap 7.0.0 - 7.5.6
Published Nov 08, 2019
Tracked Since Feb 18, 2026