PT-2024-13702 · Unknown · Visual Planning Admin Center
David Brown
+1
·
Published
2024-09-03
·
Updated
2024-10-24
·
CVE-2023-49233
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Visual Planning Admin Center 8 versions prior to v.1 Build 240207
Description
The issue is related to insufficient access checks, allowing attackers with non-administrative accounts to utilize functions normally reserved for administrators. This can lead to the obtainment of different types of configured credentials and potentially elevate their privileges to administrator level.
Recommendations
For versions prior to v.1 Build 240207, update to version v.1 Build 240207 or later to resolve the issue. As a temporary workaround, consider restricting access to administrative functions to minimize the risk of exploitation.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Visual Planning Admin Center