PT-2023-4915 · Unknown · Super Store Finder

Published

2023-09-04

·

Updated

2023-09-11

·

CVE-2023-41508

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Super Store Finder version 3.6
Description The issue is related to the use of hardcoded credentials in the Super Store Finder Google Maps API integration, allowing a remote attacker to gain access to the administration panel. A hardcoded password in the software enables attackers to access the administration panel.
Recommendations For Super Store Finder version 3.6, consider changing the hardcoded password to a unique and secure one, or updating the software to remove the hardcoded credential if a newer version addresses this issue. As a temporary workaround, restrict access to the administration panel to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

BDU:2023-05422
CVE-2023-41508

Affected Products

Super Store Finder