Логотип exploitDog
bind:CVE-2023-53740
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-53740

Количество 2

Количество 2

nvd логотип

CVE-2023-53740

9 дней назад

Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without providing the current credentials. Attackers can exploit the userManager.cgx endpoint by sending a crafted JSON request with a new MD5-hashed password to directly modify the admin account.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xxv3-3qj7-23pv

9 дней назад

Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without providing the current credentials. Attackers can exploit the userManager.cgx endpoint by sending a crafted JSON request with a new MD5-hashed password to directly modify the admin account.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-53740

Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without providing the current credentials. Attackers can exploit the userManager.cgx endpoint by sending a crafted JSON request with a new MD5-hashed password to directly modify the admin account.

CVSS3: 9.8
0%
Низкий
9 дней назад
github логотип
GHSA-xxv3-3qj7-23pv

Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without providing the current credentials. Attackers can exploit the userManager.cgx endpoint by sending a crafted JSON request with a new MD5-hashed password to directly modify the admin account.

CVSS3: 9.8
0%
Низкий
9 дней назад

Уязвимостей на страницу