PT-2023-1633 · Unknown · Mxsecurity

Esj4Y

·

Published

2023-03-08

·

Updated

2023-06-02

·

CVE-2023-33236

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions MXsecurity version 1.0
Description The issue is related to hardcoded credentials in MXsecurity, which can be exploited to craft arbitrary JWT tokens and bypass authentication for web-based APIs. This allows a remote attacker to elevate their privileges.
Recommendations For MXsecurity version 1.0, consider disabling the use of hardcoded credentials and JWT token generation until a patch is available. Restrict access to web-based APIs to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

BDU:2023-01149
CVE-2023-33236
ZDI-23-720

Affected Products

Mxsecurity