PT-2023-7563 · Boltwire · Boltwire

David Silva

·

Publicado

2023-10-31

·

Atualizado

2024-09-05

·

CVE-2023-46501

CVSS v2.0

9.4

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions BoltWire version 6.03
Description The issue in BoltWire allows a remote attacker to obtain sensitive information via a crafted payload to the view and change admin password function. This is related to insufficient protection of service data, which can be exploited by a remote attacker to gain access to confidential data.
Recommendations For BoltWire version 6.03, update the BoltWire CMS to a newer version to resolve the issue. As a temporary workaround, consider restricting access to the admin password change function until the update is applied.

Exploit

Correção

Improper Access Control

Information Disclosure

Incorrect Privilege Assignment

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-08619
CVE-2023-46501

Produtos afetados

Boltwire