CVE-2017-14653

Publication date

2017-09-22 07:00:00

Family

mitre

State

PUBLISHED

Description

member/Orderinfo.asp in ASP4CMS AspCMS 2.7.2 allows remote authenticated users to read arbitrary order information via a modified OrderNo parameter.