CVE-2007-0313Gosa vulnerability

4 documents4 sources
Severity
9.0CRITICALNVD
EPSS
0.6%
top 29.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 18
Latest updateMay 1

Description

Unspecified vulnerability in GONICUS System Administration (GOsa) before 2.5.8 allows remote authenticated users to modify certain settings, including the admin password, via crafted POST requests.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 8.0 | Impact: 10.0

Affected Packages3 packages

debiandebian/gosa< gosa 2.5.8-1 (bookworm)
Debiangosa_project/gosa< 2.5.8-1+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-wf6x-4rj3-9mpq: Unspecified vulnerability in GONICUS System Administration (GOsa) before 22022-05-01
OSV
CVE-2007-0313: Unspecified vulnerability in GONICUS System Administration (GOsa) before 22007-01-18

📋Vendor Advisories

1
Debian
CVE-2007-0313: gosa - Unspecified vulnerability in GONICUS System Administration (GOsa) before 2.5.8 a...2007