Description
The vulnerability allows an authenticated remote attacker to list arbitrary folders in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request.
By abusing this vulnerability, it is possible to steal session cookies of other active users.
By abusing this vulnerability, it is possible to steal session cookies of other active users.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-52318 | The vulnerability allows an authenticated remote attacker to list arbitrary folders in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request. By abusing this vulnerability, it is possible to steal session cookies of other active users. |
References
History
Tue, 17 Jun 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Bosch
Subscribe
Nexo-os
Subscribe
Nexo Cordless Nutrunner Nxa011s-36v-b \(0608842012\)
Subscribe
Nexo Cordless Nutrunner Nxa011s-36v \(0608842011\)
Subscribe
Nexo Cordless Nutrunner Nxa015s-36v-b \(0608842006\)
Subscribe
Nexo Cordless Nutrunner Nxa015s-36v \(0608842001\)
Subscribe
Nexo Cordless Nutrunner Nxa030s-36v-b \(0608842007\)
Subscribe
Nexo Cordless Nutrunner Nxa030s-36v \(0608842002\)
Subscribe
Nexo Cordless Nutrunner Nxa050s-36v-b \(0608842008\)
Subscribe
Nexo Cordless Nutrunner Nxa050s-36v \(0608842003\)
Subscribe
Nexo Cordless Nutrunner Nxa065s-36v-b \(0608842014\)
Subscribe
Nexo Cordless Nutrunner Nxa065s-36v \(0608842013\)
Subscribe
Nexo Cordless Nutrunner Nxp012qd-36v-b \(0608842010\)
Subscribe
Nexo Cordless Nutrunner Nxp012qd-36v \(0608842005\)
Subscribe
Nexo Cordless Nutrunner Nxv012t-36v-b \(0608842016\)
Subscribe
Nexo Cordless Nutrunner Nxv012t-36v \(0608842015\)
Subscribe
Nexo Special Cordless Nutrunner \(0608pe2272\)
Subscribe
Nexo Special Cordless Nutrunner \(0608pe2301\)
Subscribe
Nexo Special Cordless Nutrunner \(0608pe2514\)
Subscribe
Nexo Special Cordless Nutrunner \(0608pe2515\)
Subscribe
Nexo Special Cordless Nutrunner \(0608pe2666\)
Subscribe
Nexo Special Cordless Nutrunner \(0608pe2673\)
Subscribe
Status: PUBLISHED
Assigner: bosch
Published:
Updated: 2025-06-17T20:59:13.141Z
Reserved: 2023-11-13T13:44:23.702Z
Link: CVE-2023-48249
Updated: 2024-08-02T21:23:39.080Z
Status : Modified
Published: 2024-01-10T11:15:10.090
Modified: 2024-11-21T08:31:18.600
Link: CVE-2023-48249
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD