Description
JFrog Artifactory prior to 7.31.10, is vulnerable to Broken Access Control where a Project Admin is able to create, edit and delete Repository Layouts while Repository Layouts configuration should only be available for Platform Administrators.
Remediation
References
Related Vulnerabilities
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0185)
MySQL CVE-2012-0484 Vulnerability (CVE-2012-0484)
WordPress Plugin PixCodes Cross-Site Scripting (2.3.6)
WordPress Plugin WP Fastest Cache SQL Injection (0.8.7.4)
WordPress 4.4.x Cross-Site Scripting Vulnerability (4.4 - 4.4.2)