Description
Privilege Defined With Unsafe Actions, Missing Authentication for Critical Function vulnerability in Universal Software Inc. FlexCity/Kiosk allows Accessing Functionality Not Properly Constrained by ACLs, Privilege Escalation.This issue affects FlexCity/Kiosk: from 1.0 before 1.0.36.
Problem types
CWE-267 Privilege Defined With Unsafe Actions
CWE-306 Missing Authentication for Critical Function
Product status
1.0 (custom) before 1.0.36
Credits
İbrahim YİĞİTSOY
References
www.usom.gov.tr/bildirim/tr-26-0065