PT-2023-32513 · Shenzhen Youkate Industrial · Shenzhen Youkate Industrial Facial Love Cloud Payment System

Gatsby

·

Publicado

2023-11-13

·

Atualizado

2024-05-17

·

CVE-2023-6099

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Shenzhen Youkate Industrial Facial Love Cloud Payment System versions up to 1.0.55.0.0.1
Description A critical vulnerability has been found in the Shenzhen Youkate Industrial Facial Love Cloud Payment System. This issue affects an unknown part of the file /SystemMng.ashx of the component Account Handler. The manipulation of the operatorRole argument with the input 00 leads to improper privilege management. It is possible to initiate the attack remotely.
Recommendations For Shenzhen Youkate Industrial Facial Love Cloud Payment System versions up to 1.0.55.0.0.1, as a temporary workaround, consider restricting access to the /SystemMng.ashx file until a patch is available. Additionally, avoid using the operatorRole argument with the input 00 in the affected component Account Handler to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-6099

Produtos afetados

Shenzhen Youkate Industrial Facial Love Cloud Payment System