PT-2023-25932 · Weintek · Weintek Weincloud
Hank Chen
·
Published
2023-07-19
·
Updated
2023-07-26
·
CVE-2023-37362
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Weintek Weincloud version 0.13.6
Description
The issue allows an attacker to abuse the registration functionality to login with testing credentials to the official website.
Recommendations
For Weintek Weincloud version 0.13.6, consider restricting access to the registration functionality until a patch is available. As a temporary workaround, avoid using testing credentials for login purposes. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insufficiently Protected Credentials
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Weintek Weincloud