Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2281 allows any remote attacker to retrieve password of any admin or normal user in plain text format.
History

Fri, 10 Jan 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-05-31T00:00:00

Updated: 2025-01-10T14:58:57.137Z

Reserved: 2023-05-22T00:00:00

Link: CVE-2023-33730

cve-icon Vulnrichment

Updated: 2024-08-02T15:47:06.804Z

cve-icon NVD

Status : Modified

Published: 2023-05-31T20:15:10.630

Modified: 2025-01-10T15:15:13.270

Link: CVE-2023-33730

cve-icon Redhat

No data.