CVE-2018-13859 | Trivum MusicCenter up to 8.75 setAttribute.xml ?id=0/attr=protectAccess/newValue=0 access control (EDB-45088)
A vulnerability classified as critical has been found in Trivum MusicCenter up to 8.75. Affected is an unknown function of the file "/xml/system/setAttribute.xml. The manipulation of the argument ?id=0/attr=protectAccess/newValue=0 as part of GET Request leads to improper access controls.
This vulnerability is traded as CVE-2018-13859. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.