MEDIUM
vFairs 3.3 is affected by Insecure Permissions
Published May 26, 2021
4.3
MEDIUMCVSS 3.1
EPSS 0.77%
Description
vFairs 3.3 is affected by Insecure Permissions. Any user logged in to a vFairs virtual conference or event can modify any other users profile information or profile picture. After receiving any user's unique identification number and their own, an HTTP POST request can be made update their profile description or supply a new profile image. This can lead to potential cross-site scripting attacks on any user, or upload malicious PHP webshells as "profile pictures." The user IDs can be easily determined by other responses from the API for an event or chat room.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://api.vfairs.com/v1/profiles Vendor Advisory
- https://api.vfairs.com/v1/profiles?access_key= Vendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-19221 Advisory
- https://www.huntress.com/blog/zero-day-vulnerabilities-in-popular-event-management-platforms-could-leave-msps-open-to-attack Third Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://api.vfairs.com/v1/profiles | Vendor Advisory | |
| https://api.vfairs.com/v1/profiles?access_key= | Vendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-19221 | Advisory | |
| https://www.huntress.com/blog/zero-day-vulnerabilities-in-popular-event-management-platforms-could-leave-msps-open-to-attack | Third Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 26, 2021
Updated Jul 9, 2026
Reserved Oct 7, 2020
Link CVE-2020-26679
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data