
Proof-of-concept exploit for CVE-2019-19550, a remote authentication bypass in Senior Rubiweb 6.2.34.28/37, enabling unauthorized admin access to sensitive information via crafted URLs.
Remote Authentication Bypass in Senior Rubiweb 6.2.34.28 and 6.2.34.37 allows admin access to sensitive information of affected users using vulnerable versions. The attacker only needs to provide the correct URL.
Incorrect Access Control
Senior
Rubiweb
Remote
True
Access to sensitive information is publicly available without special requirements (only the correct URI)
True
Mauricio Santos (R&D UnderProtection) and Hesron Hori (R&D UnderProtection)
Senior - Vendor's Information Security Team who collaborated to a coordinated disclosure