PT-2023-23471 · Unknown · Marukyu Line

Published

2023-07-11

·

Updated

2023-07-18

·

CVE-2023-31818

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Marukyu Line version 13.4.1
Description The issue allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp function.
Recommendations For Marukyu Line version 13.4.1, consider restricting access to the miniapp function until a patch is available. Avoid using the channel access token in the miniapp function to minimize the risk of exploitation.

Exploit

Fix

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-31818

Affected Products

Marukyu Line