PT-2023-31012 · Franklin Fueling Systems · Franklin Fueling Systems System Sentinel Anyware

Published

2023-12-07

·

Updated

2023-12-12

·

CVE-2023-48929

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Franklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492
Description The issue allows an attacker to escalate privileges and obtain sensitive information through a Session Fixation vulnerability. The sid parameter in the "group status.asp" resource is vulnerable to this attack.
Recommendations For version 1.6.24.492, consider restricting access to the sid parameter in the "group status.asp" resource to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Session Fixation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-48929

Affected Products

Franklin Fueling Systems System Sentinel Anyware