Vulnerabilities > CVE-2019-18626 - Authorization Bypass Through User-Controlled Key vulnerability in Harriscomputer Ormed MIS
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
LOW Integrity impact
NONE Availability impact
NONE Summary
Harris Ormed Self Service before 2019.1.4 allows an authenticated user to view W-2 forms belonging to other users via an arbitrary empNo value to the ORMEDMIS/Data/PY/T4W2Service.svc/RetrieveW2EntriesForEmployee URI, thus exposing sensitive information including employee tax information, social security numbers, home addresses, and more.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |