Логотип exploitDog
bind:CVE-2023-53740
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-53740

Количество 2

Количество 2

nvd логотип

CVE-2023-53740

2 месяца назад

Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without providing the current credentials. Attackers can exploit the userManager.cgx endpoint by sending a crafted JSON request with a new MD5-hashed password to directly modify the admin account.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xxv3-3qj7-23pv

2 месяца назад

Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without providing the current credentials. Attackers can exploit the userManager.cgx endpoint by sending a crafted JSON request with a new MD5-hashed password to directly modify the admin account.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-53740

Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without providing the current credentials. Attackers can exploit the userManager.cgx endpoint by sending a crafted JSON request with a new MD5-hashed password to directly modify the admin account.

CVSS3: 9.8
1%
Низкий
2 месяца назад
github логотип
GHSA-xxv3-3qj7-23pv

Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without providing the current credentials. Attackers can exploit the userManager.cgx endpoint by sending a crafted JSON request with a new MD5-hashed password to directly modify the admin account.

CVSS3: 9.8
1%
Низкий
2 месяца назад

Уязвимостей на страницу