PT-2023-1633 · Unknown · Mxsecurity

Esj4Y

·

Publicado

2023-03-08

·

Atualizado

2023-06-02

·

CVE-2023-33236

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions MXsecurity version 1.0
Description The issue is related to hardcoded credentials in MXsecurity, which can be exploited to craft arbitrary JWT tokens and bypass authentication for web-based APIs. This allows a remote attacker to elevate their privileges.
Recommendations For MXsecurity version 1.0, consider disabling the use of hardcoded credentials and JWT token generation until a patch is available. Restrict access to web-based APIs to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-01149
CVE-2023-33236
ZDI-23-720

Produtos afetados

Mxsecurity