CVE-2017-7313: Personify PERSONIFY360 E-Business
High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.
An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, it is possible to read any customer name, master Customer Id, and email address. In other words, anyone can search for users/customers in the system - no authentication is required.
Affected products
- Personify PERSONIFY360 E-Business: up to and including 7.6.1
Published 2017-06-07. Last modified 2026-06-17.