The vulnerability allows a remote authenticated attacker to read or update arbitrary content of the authentication database via a crafted HTTP request.
By abusing this vulnerability it is possible to exfiltrate other users’ password hashes or update them with arbitrary values and access their accounts.
CVSS
No CVSS.
References
Configurations
No configuration.
Information
Published : 2024-01-10 13:15
Updated : 2024-01-10 13:56
NVD link : CVE-2023-48253
Mitre link : CVE-2023-48253
JSON object : View
Products Affected
No product.
CWE
No CWE.
