CVE Published: 03/10/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: CyberDanube |
Vendor: PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH |
Product: cashIT! - serving solutions. Status : PUBLISHED
CVE-2023-3654 Description
cashIT! - serving solutions. Devices from "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH" to 03.A06rks 2023.02.37 are affected by a origin bypass via the host header in an HTTP request. This vulnerability can be triggered by an HTTP endpoint exposed to the network.
Metrics
CVSS Version: 3.1 |
Base Score: 9.4 CRITICAL Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L