CVE-2023-39446

Published at:
2023-09-18T21:15:56.117

Global infos:

Thanks to the weaknesses that the web application has at the user management level, an attacker could obtain the information from the headers that is necessary to create specially designed URLs and originate malicious actions when a legitimate user is logged into the web application.

CVE Status: Modified

References:

  • [email protected]
  • af854a3a-2127-422b-91ae-364da2661108
  • Metrics:

    AttributeValue
    Attack ComplexityLOW
    Attack VectorNETWORK
    Availability ImpactHIGH
    Base Score8.9
    Base SeverityHIGH
    Confidentiality ImpactLOW
    Integrity ImpactHIGH
    Privileges RequiredLOW
    ScopeCHANGED
    User InteractionREQUIRED
    Vector StringCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:H
    Exploitability Score2.3
    Impact Score6
    Source[email protected]
    TypeSecondary

    Links:

    Exploit-db
    Github