ZeroHour

CVE-2023-47315

PoC
CVSS 3.1
8.8 high
EPSS
<1%p54
Published
()
Modified
Description

Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control due to a hard-coded JWT Secret. The secret is hardcoded into the source code available to anyone on Git Hub. This secret is used to sign the application’s JWT token and verify the incoming user-supplied tokens.

Vendors
h-mdm
Products
headwind mdm
Weakness
CWE-798
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.