PT-2023-30716 · Unknown · Websiteguide

CVE-2023-48176

·

Publicado

2023-11-20

·

Atualizado

2023-11-30

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WebsiteGuide version 0.2
Description An issue with insecure permissions in WebsiteGuide allows a remote attacker to gain escalated privileges by using a crafted JSON web token (jwt).
Recommendations For WebsiteGuide version 0.2, consider restricting access to sensitive areas of the application until a patch is available, and avoid using crafted JSON web tokens (jwt) to prevent privilege escalation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2023-48176

Produtos afetados

Websiteguide