SimpleHRM 'user_manager.php' Authentication Bypass Vulnerability
BID:59255
CVE-2013-2499 |Info
SimpleHRM 'user_manager.php' Authentication Bypass Vulnerability
| Bugtraq ID: | 59255 |
| Class: | Unknown |
| CVE: |
CVE-2013-2499 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 17 2013 12:00AM |
| Updated: | Apr 17 2013 12:00AM |
| Credit: | Doraemon Sk8ers |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
SimpleHRM 'user_manager.php' Authentication Bypass Vulnerability
SimpleHRM is prone to an authentication-bypass vulnerability.
Successful exploits may allow an attacker to bypass the authentication process to access information without proper authentication.
Versions prior to SimpleHRM 2.3 are vulnerable.
SimpleHRM is prone to an authentication-bypass vulnerability.
Successful exploits may allow an attacker to bypass the authentication process to access information without proper authentication.
Versions prior to SimpleHRM 2.3 are vulnerable.
Exploit / POC
SimpleHRM 'user_manager.php' Authentication Bypass Vulnerability
An attacker can exploit this issue using a browser.
An attacker can exploit this issue using a browser.
Solution / Fix
SimpleHRM 'user_manager.php' Authentication Bypass Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
SimpleHRM 'user_manager.php' Authentication Bypass Vulnerability
References:
References: