PT-2023-24375 · Advent/Ssc · Tamale Rms

Christopher J. Barretto

·

Published

2023-06-05

·

Updated

2025-01-08

·

CVE-2023-33524

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Advent/SSC Inc. Tamale RMS versions prior to 23.1
Description The issue allows for Directory Traversal, enabling the enumeration of contact information on the host, including usernames, e-mail addresses, and other internal information stored within the web application.
Recommendations For versions prior to 23.1, update to version 23.1 or later to resolve the issue.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2023-33524

Affected Products

Tamale Rms