CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.4. It may be remotely exploitable.
CVE
CVE-2007-5486
Severity
MEDIUM
CVSS
6.4
EPSS
1.22%
Original NVD Description
dotProject before 2.1 does not properly check privileges when invoking the Companies module, which allows remote attackers to access this module via a crafted URL. NOTE: some of these details are obtained from third party information.