Mystery Shopping System password reset security bypass |
NAME
Mystery Shopping System password reset security bypass
- Platforms Affected:
Shopmetrics Mystery Shopping Software 21-10
Shopmetrics Mystery Shopping Software 21-9
Shopmetrics Mystery Shopping Software 21-8
Shopmetrics Mystery Shopping Software 21-7 - Risk Level:
8.8 - Exploitability:
Proof of Concept - Consequences:
Bypass Security
DESCRIPTION
Shopmetrics Mystery Shopping System could allow a remote authenticated attacker to bypass security restrictions, caused by broken access control in the authorization scheme. By accessing the password reset functionality, an attacker could exploit this vulnerability to reset any password and hijack a user account.
CVSS 3.0 Information
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Access Vector: Network
- Access Complexity: Low
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
- Remediation Level: Official Fix
MITIGATION
Upgrade to the latest version of Mystery Shopping System (21-11 or later), available from the Shopmetrics Web site. See References.
- Reference Link:
https://seclists.org/fulldisclosure/2022/Feb/5 - Reference Link:
https://www.shopmetrics.com/Mystery_Shopping_Software.asp
If you like the site, please consider joining the telegram channel and supporting us on Patreon using the button below.