PT-2023-6470 · Unknown · I-Doit Pro+1

CVE-2023-37756

·

Publicado

2023-09-10

·

Atualizado

2023-09-20

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions I-doit pro versions 25 and below I-doit open versions 25 and below
Description The issue is related to weak password requirements for Administrator account creation in the affected software. This weakness allows attackers to easily guess users' passwords via a bruteforce attack. Additionally, the vulnerability may enable a remote attacker to execute arbitrary code by uploading a malicious plugin.
Recommendations For I-doit pro versions 25 and below: Update the password requirements for Administrator account creation to prevent easy guessing via bruteforce attacks. For I-doit open versions 25 and below: Update the password requirements for Administrator account creation to prevent easy guessing via bruteforce attacks. As a temporary workaround, consider restricting access to the admin-center component to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-07194
CVE-2023-37756

Produtos afetados

I-Doit Open
I-Doit Pro