PT-2023-32949 · Folio · Mod-Data-Export-Spring

CVE-2024-23687

·

Published

2023-07-25

·

Updated

2025-11-29

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions FOLIO mod-data-export-spring versions before 1.5.4 FOLIO mod-data-export-spring versions from 2.0.0 to 2.0.2
Description The issue concerns hard-coded credentials in the mod-data-export-spring module, allowing unauthenticated users to access critical APIs. This results in unauthorized access to potentially dangerous APIs, enabling the modification of user data, configurations including single-sign-on, and the manipulation of fees/fines in a patron's account. The module creates a system user for internal operations, and the hard-coded credentials for this user make it easy to authenticate and gain unauthorized access.
Recommendations For FOLIO mod-data-export-spring versions before 1.5.4, upgrade to version 1.5.4 or later. For FOLIO mod-data-export-spring versions from 2.0.0 to 2.0.2, upgrade to version 2.0.2 or later.

Exploit

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-23687
GHSA-9RHQ-86FM-QXQC
GHSA-VF78-3Q9F-92G3

Affected Products

Mod-Data-Export-Spring