logo

274 Restricted fields manipulation


Description

From the self-management functionality for the registration of an employee, it is possible to change the information of other employees from other companies. An attacker can initiate a request to confirm the registration of an employee and change the DNI to different values so that it replaces the existing data. In this way the information sent will be stored in the company, updating all the information of the targeted employees such as names, e-mail addresses, dates of birth, addresses, telephone numbers, among others.


Impact

Modify or replace the information of other employees independently of the company.


Recommendation

Verify that the user who is trying to modify the information has the necessary permissions to access.


Threat

External attacker with access to employees information.


Expected Remediation Time

15 minutes.


Score 4.0

Default score using CVSS 4.0. It may change depending on the context of the src.

Base 4.0

  • Attack vector: N
  • Attack complexity: L
  • Attack Requirements: N
  • Privileges required: H
  • User interaction: N
  • Confidentiality (VC): N
  • Integrity (VI): H
  • Availability (VA): N
  • Confidentiality (SC): N
  • Integrity (SI): N
  • Availability (SA): N

Threat 4.0

  • Exploit maturity: X

Requirements


Fixes


Last updated

2024/02/18