CVE-2022-38168 Information
Nov 04, 2022
cve
Description
UNSUPPORTED WHEN ASSIGNED Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote unauthenticated attackers to bypass the login page access sensitive information and reset user passwords via URL modification.
Reference
https://medium.com/@rob_nes/avaya-scopia-pathfinder-broken-access-control-ac792e995bae
Share on: