The advisory details a privilege escalation vulnerability in FileBound On-Site, where an authenticated user can reset the password of any local user by modifying the UserID value in a SOAP request to the SetPassword2 web service method.
Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target:FileBound On-Site (versions prior to 6.2)
Auth required
Prerequisites:Valid credentials for authentication