First published: Mon Feb 03 2020(Updated: )
Prototype 1.6.0.1 allows remote authenticated users to forge ticket creation (on behalf of other user accounts) via a modified email ID field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Prototype JavaScript Framework | =1.6.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-7993 has been classified as a medium severity vulnerability.
To fix CVE-2020-7993, upgrade the Prototype JavaScript Framework to version 1.6.0.2 or later.
CVE-2020-7993 affects accounts of remote authenticated users who can forge ticket creation for other users.
Yes, CVE-2020-7993 can potentially allow unauthorized access through ticket forgery.
CVE-2020-7993 is primarily a server-side vulnerability within the Prototype JavaScript Framework.