PT-2023-2966 · Faronics · Faronics Insight

CVE-2023-28344

·

Publicado

2023-02-01

·

Atualizado

2025-01-14

CVSS v3.1

7.1

Alta

VetorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Faronics Insight version 10.0.19045
Description The issue allows unauthenticated attackers to view constantly updated screenshots of student desktops without their consent, potentially accessing sensitive or personal data. Attackers can also submit falsified screenshots on behalf of students, hiding the actual contents of their desktops from the Teacher Console. The vulnerability is related to insufficient access control when handling the agent id parameter, which can be exploited by sending specially crafted HTTP requests.
Recommendations For Faronics Insight version 10.0.19045, consider restricting access to the Teacher Console application to prevent unauthorized viewing and submission of screenshots until a patch is available. As a temporary workaround, restrict the use of the agent id parameter to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Exposure of Resource to Wrong Sphere

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-02978
CVE-2023-28344

Produtos afetados

Faronics Insight