PT-2023-30273 · Unknown · Yunfan Learning Examination System
Binxiang Wei
·
Publicado
2023-11-04
·
Atualizado
2023-11-14
·
CVE-2023-46963
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Yunfan Learning Examination System version 6.5
Description
The issue allows a remote attacker to obtain sensitive information via the
password parameter in the login function.Recommendations
For Yunfan Learning Examination System version 6.5, consider restricting access to the login function until a patch is available. As a temporary workaround, avoid using the
password parameter in the affected login function to minimize the risk of exploitation.Exploit
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Yunfan Learning Examination System