An issue was discovered in /fcgi/scrut_fcgi.fcgi in Plixer Scrutinizer before 19.3.1. The csvExportReport endpoint action generateCSV does not require authentication and allows an unauthenticated user to export a report and access the results.
Metrics
Affected Vendors & Products
References
History
Thu, 19 Sep 2024 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2023-10-12T00:00:00
Updated: 2024-09-18T14:24:24.567Z
Reserved: 2023-08-25T00:00:00
Link: CVE-2023-41261
Vulnrichment
Updated: 2024-08-02T18:54:05.194Z
NVD
Status : Modified
Published: 2023-10-12T23:15:11.137
Modified: 2024-11-21T08:20:56.287
Link: CVE-2023-41261
Redhat
No data.