Description
SmartStar Software CWS is a web-based integration platform, it has a vulnerability of missing authorization and users are able to access data or perform actions that they should not be allowed to perform via commands. An authenticated with normal user privilege can execute administrator privilege, resulting in performing arbitrary system operations or disrupting service.
No analysis available yet.
Remediation
Vendor Solution
Update to the latest version.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-52427 | SmartStar Software CWS is a web-based integration platform, it has a vulnerability of missing authorization and users are able to access data or perform actions that they should not be allowed to perform via commands. An authenticated with normal user privilege can execute administrator privilege, resulting in performing arbitrary system operations or disrupting service. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-7594-dac20-1.html |
|
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-08-02T21:30:34.755Z
Reserved: 2023-11-16T03:49:45.971Z
Link: CVE-2023-48375
No data.
Status : Modified
Published: 2023-12-15T08:15:45.000
Modified: 2024-11-21T08:31:35.743
Link: CVE-2023-48375
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD