[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[FD] Scrumworks Pro authenticated arbitrary password reset
- To: "fulldisclosure@xxxxxxxxxxxx" <fulldisclosure@xxxxxxxxxxxx>
- Subject: [FD] Scrumworks Pro authenticated arbitrary password reset
- From: Brandon Perry <bperry.volatile@xxxxxxxxx>
- Date: Thu, 5 Jun 2014 09:59:39 -0500
The latest available version of Scrumworks Pro does not perform proper
authorization checks when users attempt to change passwords via the Java
Web Start client.
If you capture the request the web start client makes when changing the
'administrator' user's password, and substitute the JSESSIONID cookie with
that of another, lesser privileged authenticated user's JSESSIONID cookie,
making the request will still result in the administrator user's password
to be changed.
I hope to have a Metasploit module available this evening.
--
http://volatile-minds.blogspot.com -- blog
http://www.volatileminds.net -- website
_______________________________________________
Sent through the Full Disclosure mailing list
http://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/