PT-2023-4915 · Unknown · Super Store Finder
Published
2023-09-04
·
Updated
2023-09-11
·
CVE-2023-41508
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Super Store Finder version 3.6
Description
The issue is related to the use of hardcoded credentials in the Super Store Finder Google Maps API integration, allowing a remote attacker to gain access to the administration panel. A hardcoded password in the software enables attackers to access the administration panel.
Recommendations
For Super Store Finder version 3.6, consider changing the hardcoded password to a unique and secure one, or updating the software to remove the hardcoded credential if a newer version addresses this issue. As a temporary workaround, restrict access to the administration panel to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Access Control
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Super Store Finder