CVE-2016-15002

A vulnerability, which was classified as critical, was found in MONyog Ultimate 6.63. This affects an unknown part of the component Cookie Handler. The manipulation of the argument HasServerEdit/IsAdmin leads to privilege escalation. It is possible to initiate the attack remotely.
References
Link Resource
https://vuldb.com/?id.98355 Third Party Advisory
https://youtu.be/KKlwi-u6wyA Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:ideracorp:webyog_monyog_ultimate:6.63:*:*:*:*:*:*:*

History

15 Jun 2022, 18:23

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 6.5
v3 : 8.8
CPE cpe:2.3:a:ideracorp:webyog_monyog_ultimate:6.63:*:*:*:*:*:*:*
References (MISC) https://youtu.be/KKlwi-u6wyA - (MISC) https://youtu.be/KKlwi-u6wyA - Exploit, Third Party Advisory
References (MISC) https://vuldb.com/?id.98355 - (MISC) https://vuldb.com/?id.98355 - Third Party Advisory
First Time Ideracorp
Ideracorp webyog Monyog Ultimate
CWE CWE-565

09 Jun 2022, 17:34

Type Values Removed Values Added
New CVE

Information

Published : 2022-06-09 17:15

Updated : 2023-12-10 14:22


NVD link : CVE-2016-15002

Mitre link : CVE-2016-15002

CVE.ORG link : CVE-2016-15002


JSON object : View

Products Affected

ideracorp

  • webyog_monyog_ultimate
CWE
CWE-565

Reliance on Cookies without Validation and Integrity Checking

CWE-269

Improper Privilege Management