PT-2023-22637 · Mobatime · Mobatime

Testeurdestylos

·

Published

2023-06-02

·

Updated

2023-06-10

·

CVE-2023-3033

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mobatime web application versions through 06.7.22
Description The issue is related to an Incorrect Authorization vulnerability in the Mobatime web application, allowing Privilege Escalation due to Exploiting Incorrectly Configured Access Control Security Levels.
Recommendations For versions through 06.7.22, consider restricting access to sensitive areas of the web application to minimize the risk of exploitation until a patch is available. As a temporary workaround, review and correct the configuration of Access Control Security Levels to prevent privilege escalation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-3033

Affected Products

Mobatime