PT-2023-31169 · Wolters Kluwer · Wolters Kluwer B.Point

Alessandro Sabetta

+4

·

Published

2023-12-25

·

Updated

2024-01-03

·

CVE-2023-49328

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Wolters Kluwer B.POINT version 23.70.00
Description The issue allows a validated system user to achieve remote code execution via Argument Injection in the server-to-server module during the authentication phase.
Recommendations For version 23.70.00, consider restricting access to the server-to-server module to minimize the risk of exploitation until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2023-49328

Affected Products

Wolters Kluwer B.Point