PT-2023-14300 · Gx · Xperiencentral

CVE-2022-43712

·

Publicado

2023-07-26

·

Atualizado

2023-08-04

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions GX Software XperienCentral versions 10.36.0 and earlier
Description The issue allows unauthorized users to post data to the server by sending POST requests to the /web/mvc endpoint if they can bypass other security filters.
Recommendations For GX Software XperienCentral versions 10.36.0 and earlier, consider blocking unauthorized POST requests to the /web/mvc endpoint to prevent unauthorized data from being posted to the server. As a temporary workaround, restrict access to this endpoint for unauthenticated users until a fix is available.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-43712

Produtos afetados

Xperiencentral