The application suffers from improper access control when editing users.
A user with read permissions can manipulate users, passwords, and
permissions by sending a single HTTP POST request with modified
parameters.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-49534 | The application suffers from improper access control when editing users. A user with read permissions can manipulate users, passwords, and permissions by sending a single HTTP POST request with modified parameters. |
Solution
No solution given by the vendor.
Workaround
Sielco has not responded to requests to work with CISA to mitigate these vulnerabilities. Users of affected versions of Sielco PolyEco FM Transmitter are invited to contact Sielco customer support https://www.sielco.org/en/contacts for additional information.
Thu, 16 Jan 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-01-16T21:28:09.489Z
Reserved: 2023-10-25T15:23:55.527Z
Link: CVE-2023-45228
Updated: 2024-08-02T20:14:19.919Z
Status : Modified
Published: 2023-10-26T17:15:09.087
Modified: 2024-11-21T08:26:35.447
Link: CVE-2023-45228
No data.
OpenCVE Enrichment
No data.
EUVD