CVE-2019-19989
Summary
| CVE | CVE-2019-19989 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-26 16:15:00 UTC |
| Updated | 2020-02-27 13:59:00 UTC |
| Description | An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Several PHP pages, and other type of files, are reachable by any user without checking for user identity and authorization. |
Risk And Classification
Problem Types: CWE-862
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Seling | Visual Access Manager | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Controllo accessi, rilevazione presenze e Building Security - Selesta Ingegneria | MISC | www.seling.it | Product |
| Applicativo Controllo Accessi: VAM - Selesta Ingegneria | MISC | www.seling.it | Product, Vendor Advisory |
| Gruppo TIM | Vulnerability Research & Advisor | MISC | www.telecomitalia.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.