PT-2023-3710 · Unknown · Sspanel-Uim

Agenty0

·

Published

2023-06-13

·

Updated

2023-06-23

·

CVE-2023-34965

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SSPanel-Uim version 2023.3
Description The issue is related to improper authorization in the /link/ interface of the SSPanel-Uim software. This can allow an attacker to gain access to confidential information, potentially leading to a leak of user information.
Recommendations For SSPanel-Uim version 2023.3, restrict access to the /link/ interface to prevent unauthorized access to user information. As a temporary workaround, consider disabling access to the /link/ interface until a patch is available.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2023-03998
CVE-2023-34965

Affected Products

Sspanel-Uim