PT-2023-4915 · Unknown · Super Store Finder

CVE-2023-41508

·

Publicado

2023-09-04

·

Atualizado

2023-09-11

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Super Store Finder version 3.6
Description The issue is related to the use of hardcoded credentials in the Super Store Finder Google Maps API integration, allowing a remote attacker to gain access to the administration panel. A hardcoded password in the software enables attackers to access the administration panel.
Recommendations For Super Store Finder version 3.6, consider changing the hardcoded password to a unique and secure one, or updating the software to remove the hardcoded credential if a newer version addresses this issue. As a temporary workaround, restrict access to the administration panel to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-05422
CVE-2023-41508

Produtos afetados

Super Store Finder