PT-2024-13080 · Unknown · Coign Crm Portal

Amjad Ali

·

Published

2024-01-23

·

Updated

2024-01-30

·

CVE-2023-43317

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Coign CRM Portal version 06.06
Description An issue in the software allows a remote attacker to escalate privileges via the userPermissionsList parameter in the Session Storage component.
Recommendations For Coign CRM Portal version 06.06, consider restricting access to the Session Storage component to minimize the risk of exploitation. Avoid using the userPermissionsList parameter until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2023-43317

Affected Products

Coign Crm Portal