9.8

CVE-2023-3069

Exploit

Unverified Password Change in tsolucio/corebos

Unverified Password Change in GitHub repository tsolucio/corebos prior to 8.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CorebosCorebos Version < 8.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.6% 0.438
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
security@huntr.dev 7.6 2.8 4.7
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

CWE-620 Unverified Password Change

When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.

https://github.com/tsolucio/corebos/commit/e3dabd74c68646bb54538d66411fc1e633ec454b
Patch
https://huntr.dev/bounties/00544982-365a-476b-b5fe-42f02f11d367
Patch
Exploit