Amtelco miSecureMessages allows remote attackers to read the messages of arbitrary users via an XML request containing a valid license key and a modified contactID value, as demonstrated by a request from the iOS or Android application.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| amtelco | misecuremessages | - |
Amtelco miSecureMessages (aka MSM) 6.2 does not properly manage sessions, which allows remote authenticated users to obtain sensitive information via a modified message request.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-200,CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| amtelco | misecuremessages | 6.2 |