PT-2023-32513 · Shenzhen Youkate Industrial · Shenzhen Youkate Industrial Facial Love Cloud Payment System
Gatsby
·
Publicado
2023-11-13
·
Atualizado
2024-05-17
·
CVE-2023-6099
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Shenzhen Youkate Industrial Facial Love Cloud Payment System versions up to 1.0.55.0.0.1
Description
A critical vulnerability has been found in the Shenzhen Youkate Industrial Facial Love Cloud Payment System. This issue affects an unknown part of the file /SystemMng.ashx of the component Account Handler. The manipulation of the
operatorRole argument with the input 00 leads to improper privilege management. It is possible to initiate the attack remotely.Recommendations
For Shenzhen Youkate Industrial Facial Love Cloud Payment System versions up to 1.0.55.0.0.1, as a temporary workaround, consider restricting access to the /SystemMng.ashx file until a patch is available. Additionally, avoid using the
operatorRole argument with the input 00 in the affected component Account Handler to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Improper Privilege Management
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Shenzhen Youkate Industrial Facial Love Cloud Payment System