Description
SmarterTrack 7922 contains an information disclosure vulnerability in the Chat Management search form that reveals agent identification details. Attackers can access the vulnerable /Management/Chat/frmChatSearch.aspx endpoint to retrieve agents' first and last names along with their unique identifiers.
Problem types
Exposure of Sensitive System Information to an Unauthorized Control Sphere
Product status
14.x
Credits
Andrei Manole
References
www.exploit-db.com/exploits/50328
www.exploit-db.com/exploits/50328 (ExploitDB-50328)
www.smartertools.com/ (SmarterTools Official Homepage)
www.smartertools.com/smartertrack (SmarterTrack Product Page)
www.vulncheck.com/...ols-smartertrack-information-disclosure (VulnCheck Advisory: SmarterTools SmarterTrack 7922 -Information Disclosure)