PT-2023-22833 · Mobatime · Mobatime

Testeurdestylos

·

Published

2023-06-05

·

Updated

2023-06-14

·

CVE-2023-3064

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mobatime mobile application AMXGT100 versions 1.3.20 and earlier
Description The issue allows an anonymous user to obtain a list of existing users managed by the application, which could facilitate further attacks. It is related to an improper authentication vulnerability that enables authentication bypass.
Recommendations For Mobatime mobile application AMXGT100 versions 1.3.20 and earlier, update to a version that includes the fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insecure Storage of Sensitive Information

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2023-3064

Affected Products

Mobatime