TMS v2.28.0 contains an insecure permissions vulnerability via the component /TMS/admin/user/Update2. This vulnerability allows attackers to modify the administrator account and password.
References
Link Resource
https://github.com/xiweicheng/tms/issues/16 Exploit Issue Tracking Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-03-20T18:34:59

Updated: 2022-03-20T18:34:59

Reserved: 2022-02-28T00:00:00


Link: CVE-2022-26247

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-03-20T19:15:07.707

Modified: 2022-03-28T19:06:20.910


Link: CVE-2022-26247

JSON object: View

cve-icon Redhat Information

No data.

CWE