CVE-2023-48249

The vulnerability allows an authenticated remote attacker to list arbitrary folders in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request. By abusing this vulnerability, it is possible to steal session cookies of other active users.
CVSS

No CVSS.

Configurations

No configuration.

Information

Published : 2024-01-10 11:15

Updated : 2024-01-10 13:56


NVD link : CVE-2023-48249

Mitre link : CVE-2023-48249


JSON object : View

Products Affected

No product.

CWE

No CWE.