CVE-2018-13791: Abbyy Flexicapture
Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.
The HTTP API in ABBYY FlexiCapture before 12 Release 1 Update 7 allows an attacker to conduct Access Control attacks via the /FlexiCapture12/Login/Server/SevaUserProfile FlexiCaptureTmsSts2 parameter.
Affected products
- Abbyy Flexicapture: version 12.0.1.263 only; version 12.0.1.267 only; version 12.0.1.282 only; version 12.0.1.292 only; version 12.0.1.367 only; version 12.0.1.428 only; …
Published 2018-07-09. Last modified 2026-06-17.