PT-2024-27493 · Unknown · Smart Office

Ahmed8199

·

Published

2024-04-13

·

Updated

2024-07-19

·

CVE-2024-3735

CVSS v2.0

2.6

Low

VectorAV:N/AC:H/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Smart Office versions up to 20240405
Description A vulnerability was found in the file Main.aspx, where the manipulation of the New Password/Confirm Password argument with the input 1 leads to weak password requirements. The attack can be launched remotely, with a rather high complexity and difficult exploitability. The exploit has been disclosed to the public and may be used.
Recommendations For versions up to 20240405, consider temporarily restricting the use of the New Password/Confirm Password argument until a patch is available. As a mitigation measure, ensure strong password requirements are enforced to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

CVE-2024-3735

Affected Products

Smart Office