Iagona ScrutisWeb versions 2.1.37 and prior are vulnerable to an insecure direct object reference vulnerability that could allow an unauthenticated user to view profile information, including user login names and encrypted passwords.
History

Mon, 28 Oct 2024 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2023-07-18T17:17:29.939Z

Updated: 2024-10-28T15:29:08.494Z

Reserved: 2023-07-13T17:28:15.854Z

Link: CVE-2023-38257

cve-icon Vulnrichment

Updated: 2024-08-02T17:39:12.252Z

cve-icon NVD

Status : Modified

Published: 2023-07-18T18:15:12.620

Modified: 2024-11-21T08:13:11.957

Link: CVE-2023-38257

cve-icon Redhat

No data.