Vulnerabilities
Vulnerable Software
Beims:  Security Vulnerabilities
ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows access to various /UserManagement/ privileged modules without authenticating the user; an attacker can misuse these functionalities to perform unauthorized actions, as demonstrated by Edit User Details.
CVSS Score
9.8
EPSS Score
0.005
Published
2018-01-15
ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) on /CWEBNET/* authenticated pages. A successful CSRF attack can force the user to modify state: creating users, changing an email address, and so forth. If the victim is an administrative account, CSRF can compromise the entire web application.
CVSS Score
8.8
EPSS Score
0.003
Published
2018-01-15


Contact Us

Shodan ® - All rights reserved