Vulnerabilities > CVE-2022-28607 - Unspecified vulnerability in Isic.Lk Project Isic.Lk

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
isic-lk-project

Summary

An issue was discovered in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers to gain sensitive information via the action parameter to /system/user/modules/mod_users/controller.php.

Vulnerable Configurations

Part Description Count
Application
Isic.Lk_Project
1