PoC Index

CVE-2023-6773

HIGH 8.8EPSS 0.7%

A vulnerability has been found in CodeAstro POS and Inventory Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /accounts_con/register_account of the component User Creation Handler. The manipulation of the argument account_type with the input Admin leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-247909 was assigned to this vulnerability. In CodeAstro POS and Inventory Management System 1.0 wurde eine Schwachstelle gefunden. Sie wurde als problematisch eingestuft. Hierbei betrifft es unbekannten Programmcode der Datei /accounts_con/register_account der Komponente User Creation Handler. Mit der Manipulation des Arguments account_type mit der Eingabe Admin mit unbekannten Daten kann eine improper access controls-Schwachstelle ausgenutzt werden. Umgesetzt werden kann der Angriff über das Netzwerk. Der Exploit steht zur öffentlichen Verfügung.

CVSS v3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS v2.0
4.0 MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
EPSS
0.74% chance of exploitation in the next 30 days, 52th percentile
Published
2023-12-13
Updated
2024-08-02

Proof-of-concept exploits (1)

References

Related