Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-17604

An Insecure Direct Object Reference (IDOR) vulnerability in eyecomms eyeCMS through 2019-10-15 allows any candidate to change other candidates' personal information (first name, last name, email, CV, phone number, and all other personal information) by changing the value of the candidate id (the id parameter).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 45.7%
CVSS Severity
CVSS v3 Score 4.3
CVSS v2 Score 4.0
Products affected by CVE-2019-17604
  • Eyecomms » Eyecms » Version: N/A
    cpe:2.3:a:eyecomms:eyecms:-
  • Eyecomms » Eyecms » Version: 2019-10-15
    cpe:2.3:a:eyecomms:eyecms:2019-10-15


Contact Us

Shodan ® - All rights reserved