PT-2023-25932 · Weintek · Weintek Weincloud

Hank Chen

·

Published

2023-07-19

·

Updated

2023-07-26

·

CVE-2023-37362

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Weintek Weincloud version 0.13.6
Description The issue allows an attacker to abuse the registration functionality to login with testing credentials to the official website.
Recommendations For Weintek Weincloud version 0.13.6, consider restricting access to the registration functionality until a patch is available. As a temporary workaround, avoid using testing credentials for login purposes. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficiently Protected Credentials

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2023-37362

Affected Products

Weintek Weincloud