Unrated severityNVD Advisory· Published Oct 2, 2015· Updated May 6, 2026
CVE-2015-2858
CVE-2015-2858
Description
Datalex airline booking software before 2015-09-03 allows remote attackers to read or write to arbitrary user data via a modified profileId parameter to (1) ValidateFormAction.do or (2) ProfileConfirmEditAddressAction.do.
Affected products
1- cpe:2.3:a:datalex:airline_booking_software:-:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.kb.cert.org/vuls/id/693036nvdThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.