PT-2023-7563 · Boltwire · Boltwire

David Silva

·

Published

2023-10-31

·

Updated

2024-09-05

·

CVE-2023-46501

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions BoltWire version 6.03
Description The issue in BoltWire allows a remote attacker to obtain sensitive information via a crafted payload to the view and change admin password function. This is related to insufficient protection of service data, which can be exploited by a remote attacker to gain access to confidential data.
Recommendations For BoltWire version 6.03, update the BoltWire CMS to a newer version to resolve the issue. As a temporary workaround, consider restricting access to the admin password change function until the update is applied.

Exploit

Fix

Improper Access Control

Information Disclosure

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

BDU:2023-08619
CVE-2023-46501

Affected Products

Boltwire