PoC Index

CVE-2020-9384

HIGH 8.8EPSS 1.9%

An Insecure Direct Object Reference (IDOR) vulnerability in the Change Password feature of Subex ROC Partner Settlement 10.5 allows remote authenticated users to achieve account takeover via manipulation of POST parameters. NOTE: This vulnerability may only affect a testing version of the application

CVSS v3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
1.90% chance of exploitation in the next 30 days, 78th percentile
Published
2020-04-14
Updated
2024-08-04

Proof-of-concept exploits (1)

References

Related