PT-2024-13068 · Clarisa · Filemaker Server
Published
2024-04-26
·
Updated
2024-12-10
·
CVE-2023-42955
CVSS v3.1
6.1
Medium
| Vector | AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
FileMaker Server versions prior to 20.3.1
Description
The issue potentially exposed password information to front-end websites when signed in to the Admin Console with an administrator role. This was resolved by eliminating the send of Admin Role passwords in the Node.js socket.
Recommendations
For versions prior to 20.3.1, update to FileMaker Server 20.3.1 to resolve the issue. As a temporary workaround, consider restricting access to the Admin Console to minimize the risk of exploitation.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Filemaker Server