PT-2023-1633 · Unknown · Mxsecurity
Esj4Y
·
Published
2023-03-08
·
Updated
2023-06-02
·
CVE-2023-33236
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
MXsecurity version 1.0
Description
The issue is related to hardcoded credentials in MXsecurity, which can be exploited to craft arbitrary JWT tokens and bypass authentication for web-based APIs. This allows a remote attacker to elevate their privileges.
Recommendations
For MXsecurity version 1.0, consider disabling the use of hardcoded credentials and JWT token generation until a patch is available. Restrict access to web-based APIs to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mxsecurity