Vulnerability CVE-2017-6513


Published: 2017-03-11

Description:
The WHMCS Reseller Module V2 2.0.2 in Softaculous Virtualizor before 2.9.1.0 does not verify the user correctly, which allows remote authenticated users to control other virtual machines managed by Virtualizor by accessing a modified URL.

CVSS2 => (AV:N/AC:L/Au:S/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.5/10
6.4/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Softaculous -> Whmcs reseller module 

 References:
http://www.virtualizor.com/blog/?p=1551
https://gist.github.com/sedrubal/a83fa22f1091025a5c1a14aabd711ad7

Copyright 2024, cxsecurity.com

 

Back to Top