PT-2023-31011 · Franklin Fueling Systems · Franklin Fueling Systems System Sentinel Anyware

Published

2023-12-07

·

Updated

2023-12-12

·

CVE-2023-48928

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Franklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492
Description The issue allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL. This is achieved through the 'path' parameter of the prefs.asp resource.
Recommendations For version 1.6.24.492, consider restricting access to the prefs.asp resource to minimize the risk of exploitation. As a temporary workaround, avoid using the path parameter in the prefs.asp resource until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-48928

Affected Products

Franklin Fueling Systems System Sentinel Anyware