PT-2023-23754 · Otcms · Otcms
P0Ison
·
Published
2023-06-14
·
Updated
2024-05-17
·
CVE-2023-3237
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OTCMS versions up to 6.62
Description
A critical issue was discovered, affecting unknown code. The manipulation of the
username and password arguments with the input admin leads to the use of a hard-coded password.Recommendations
For OTCMS versions up to 6.62, update to a version that fixes this issue to prevent exploitation. As a temporary workaround, consider restricting access to the login functionality until a patch is available. Avoid using the default
admin credentials in the affected username and password fields until the issue is resolved.Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Otcms