PT-2023-8572 · N Able · N-Able Passportal Extension

Published

2023-10-30

·

Updated

2024-08-19

·

CVE-2023-47131

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions N-able PassPortal extension versions prior to 3.29.2 for Chrome
Description The issue is related to insufficient protection of registration data, which may allow an attacker to gain unauthorized access to protected information. The N-able PassPortal extension inserts sensitive information into a log file, potentially exposing it.
Recommendations For versions prior to 3.29.2, update to version 3.29.2 or later to resolve the issue. As a temporary workaround, consider restricting access to log files to minimize the risk of exploitation.

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

BDU:2024-01212
CVE-2023-47131

Affected Products

N-Able Passportal Extension