CVE-2015-2952
Summary
| CVE | CVE-2015-2952 |
|---|---|
| State | PUBLISHED |
| Assigner | jpcert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-06-13 15:59:02 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The user-information management functionality in Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote authenticated users to bypass intended access restrictions and modify administrative credentials via unspecified vectors, a different vulnerability than CVE-2015-2953 and CVE-2015-2958. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Igreks | Milkystep Light | All | All | All | All |
| Application | Igreks | Milkystep Professional | All | All | All | All |
| Application | Igreks | Milkystep Professional Oem | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple MilkyStep Products CVE-2015-2952 Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| jvndb.jvn.jp/jvndb/JVNDB-2015-000077 | af854a3a-2127-422b-91ae-364da2661108 | jvndb.jvn.jp | Vendor Advisory |
| JVN#19732015: MilkyStep fails to restrict access permissions | af854a3a-2127-422b-91ae-364da2661108 | jvn.jp | Vendor Advisory |
| Japan Vulnerability Notes/Information from Igreks Inc. | af854a3a-2127-422b-91ae-364da2661108 | jvn.jp | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.