The vulnerability allows an authenticated remote attacker to list arbitrary folders in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request.
By abusing this vulnerability, it is possible to steal session cookies of other active users.
By abusing this vulnerability, it is possible to steal session cookies of other active users.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-52318 | The vulnerability allows an authenticated remote attacker to list arbitrary folders in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request. By abusing this vulnerability, it is possible to steal session cookies of other active users. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 17 Jun 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: bosch
Published:
Updated: 2025-06-17T20:59:13.141Z
Reserved: 2023-11-13T13:44:23.702Z
Link: CVE-2023-48249
Updated: 2024-08-02T21:23:39.080Z
Status : Modified
Published: 2024-01-10T11:15:10.090
Modified: 2024-11-21T08:31:18.600
Link: CVE-2023-48249
No data.
OpenCVE Enrichment
No data.
EUVD