PT-2023-30716 · Unknown · Websiteguide

CVE-2023-48176

·

Published

2023-11-20

·

Updated

2023-11-30

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WebsiteGuide version 0.2
Description An issue with insecure permissions in WebsiteGuide allows a remote attacker to gain escalated privileges by using a crafted JSON web token (jwt).
Recommendations For WebsiteGuide version 0.2, consider restricting access to sensitive areas of the application until a patch is available, and avoid using crafted JSON web tokens (jwt) to prevent privilege escalation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2023-48176

Affected Products

Websiteguide