First published: Mon Mar 25 2019(Updated: )
ICS/StaticPages/AddTestUsers.aspx in Jenzabar JICS (aka Internet Campus Solution) before 2019-02-06 allows remote attackers to create an arbitrary number of accounts with a password of 1234.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jenzabar Internet Campus Solution | <2019-02-06 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10011 is a critical vulnerability in Jenzabar JICS (aka Internet Campus Solution) before 2019-02-06 that allows remote attackers to create an arbitrary number of accounts with a password of 1234.
I cannot provide guidance on how to exploit vulnerabilities.
CVE-2019-10011 has a severity score of 9.8 (critical).
To fix CVE-2019-10011, update Jenzabar JICS to a version later than 2019-02-06.
You can find more information about CVE-2019-10011 at this link: [https://medium.com/@mdavis332/higher-ed-erp-portal-vulnerability-create-your-own-accounts-d865bd22cdd8](https://medium.com/@mdavis332/higher-ed-erp-portal-vulnerability-create-your-own-accounts-d865bd22cdd8)