CVE-2012-1256: Easyvista

Medium severity, CVSS 5.0. EPSS: 1.4% chance of exploitation in the next 30 days.

The single sign-on (SSO) implementation in EasyVista before 2010.1.1.89 allows remote attackers to bypass authentication via a modified url_account parameter, in conjunction with a valid login name in the SSPI_HEADER parameter, to index.php.

Affected products

  • Easyvista Easyvista: up to and including 2010

Published 2012-02-22. Last modified 2026-06-16.