L’API HTTP in ABBYY FlexiCapture prima del 12 Release 1 Update 7 permette a un attaccante di condurre attacchi di controllo di accesso tramite il parametro / FlexiCapture12 / Login / Server / SevaUserProfile FlexiCaptureTmsSts2. |
http://abbyydownloads.com/fc12/PreviousReleaseNotes/ReleaseNotes_FC12_R1_U3_1299.18_build_12.0.1.516.pdf https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-13791 |
Vulnerabilità: CVE-2018-13791
