PT-2023-23754 · Otcms · Otcms

P0Ison

·

Published

2023-06-14

·

Updated

2024-05-17

·

CVE-2023-3237

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OTCMS versions up to 6.62
Description A critical issue was discovered, affecting unknown code. The manipulation of the username and password arguments with the input admin leads to the use of a hard-coded password.
Recommendations For OTCMS versions up to 6.62, update to a version that fixes this issue to prevent exploitation. As a temporary workaround, consider restricting access to the login functionality until a patch is available. Avoid using the default admin credentials in the affected username and password fields until the issue is resolved.

Exploit

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2023-3237

Affected Products

Otcms