Skip to content

Instantly share code, notes, and snippets.

@sm0k
sm0k / gist:5de26614282669b0bcfa719b87c17305
Created January 17, 2020 17:03
YellowBox CRM - 5.5 CVE-2019-14765 CVE-2019-14766 CVE-2019-14767 CVE-2019-14768
===========================================================================================================
Incorrect Access Control in AfficheExplorateurParam() in DIMO
YellowBox CRM before 6.3.4 allows a standard authenticated user to use
administrative controllers.
------------------------------------------
[Vulnerability Type]
Incorrect Access Control