ZeroHour

CVE-2023-39446

CVSS 3.1
8.8 high
EPSS
<1%p17
Published
()
Modified
Description

Thanks to the weaknesses that the web application has at the user management level, an attacker could obtain the information from the headers that is necessary to create specially designed URLs and originate malicious actions when a legitimate user is logged into the web application.

Vendors
socomec
Products
modulys gp firmware
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.