CVE-2007-1923 Information
Feb 14, 2021
cve
Description
(1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control lists by changing the set of URLs linked from menus which allows remote attackers to access restricted functionality via direct requests.
Reference
http://osvdb.org/38217 http://osvdb.org/38218 http://securityreason.com/securityalert/2552 http://www.securityfocus.com/archive/1/464880/100/0/threaded http://www.securityfocus.com/bid/23352 https://exchange.xforce.ibmcloud.com/vulnerabilities/33494
Share on: