CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.8. Exploitation may require the attacker to be authenticated.
CVE
CVE-2019-18623
Severity
CRITICAL
CVSS
9.8
EPSS
1.48%
Original NVD Description
Escalation of privileges in EnergyCAP 7 through 7.5.6 allows an attacker to access data. If an unauthenticated user clicks on a link on the public dashboard, the resource opens in EnergyCAP with access rights matching the user who created the dashboard.