Total vulnerabilities in the database
Hosting Controller 6.1 Hotfix 2.1 allows remote authenticated users to perform unauthorized actions, such as modifying the credit limit, via a direct request to AccountActions.asp and modifying the CreditLimit parameter in an UpdateCreditLimit action.
Software | From | Fixed in |
---|---|---|
hosting_controller / hosting_controller | 6.1_hotfix_2.1 | 6.1_hotfix_2.1.x |