CVE

Id
80135  
CVE No.
CVE-2015-2858  
Status
Candidate  
Description
Datalex airline booking software before 2015-09-03 allows remote attackers to read or write to arbitrary user data via a modified profileId parameter to (1) ValidateFormAction.do or (2) ProfileConfirmEditAddressAction.do.  
Phase
Assigned (20150403)  
Votes
None (candidate not yet proposed)  
Comments