PT-2024-13616 · Archibus · Archibus

Elliot Rasch

·

Published

2024-03-05

·

Updated

2025-05-23

·

CVE-2023-48644

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Archibus app version 4.0.3 for iOS
Description An issue was discovered in the create work request feature of the maintenance module, via the description field. This allows an attacker to perform an action on behalf of the user, exfiltrate data, and so on.
Recommendations For Archibus app version 4.0.3, consider disabling the create work request feature in the maintenance module until a patch is available. Restrict access to the description field to minimize the risk of exploitation.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2023-48644

Affected Products

Archibus