Technical Advisory – ICTFAX 7-4 – Indirect Object Reference
ID: c02bc274-7215-5553-8f0c-7c43076727fa
STIX ID: report--c02bc274-7215-5553-8f0c-7c43076727fa
Feed Name: NCC Research
Threat Score
This advisory describes an insecure direct object reference in ICTFax that allows an authenticated low-privilege user to reset any user's password (including administrators) by altering a numeric user identifier in the password-change request; the report includes reproduction steps, impact assessment, a recommendation to require current password re-entry, and a vendor disclosure timeline.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
