Vulnerabilities (CVE)

Filtered by vendor Archerirm Subscribe
Filtered by product Archer
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-48641 1 Archerirm 1 Archer 2023-12-15 N/A 8.8 HIGH
Archer Platform 6.x before 6.14 P1 HF2 (6.14.0.1.2) contains an insecure direct object reference vulnerability. An authenticated malicious user in a multi-instance installation could potentially exploit this vulnerability by manipulating application resource references in user requests to bypass authorization checks, in order to gain execute access to AWF application resources.
CVE-2023-32761 1 Archerirm 1 Archer 2023-07-27 N/A 8.0 HIGH
Cross Site Request Forgery (CSRF) vulnerability in Archer Platform before v.6.13 and fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to execute arbitrary code via a crafted request.