CVE-2023-4595 Vulnerability Details

  /     /     /  

CVE-2023-4595 Metadata Quick Info

CVE Published: 23/11/2023 | CVE Updated: 02/08/2024 | CVE Year: 2023
Source: INCIBE | Vendor: BVRP Software | Product: SLmail
Status : PUBLISHED

CVE-2023-4595 Description

An information exposure vulnerability has been found, the exploitation of which could allow a remote user to retrieve sensitive information stored on the server such as credential files, configuration files, application files, etc., simply by appending any of the following parameters to the end of the URL: %00 %0a, %20, %2a, %a0, %aa, %c0 and %ca.

Metrics

CVSS Version: 3.1 | Base Score: 7.5 HIGH
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

l➤ Exploitability Metrics:
    Attack Vector (AV)* NETWORK
    Attack Complexity (AC)* LOW
    Privileges Required (PR)* NONE
    User Interaction (UI)* NONE
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* HIGH
    Integrity Impact (I)* NONE
    Availability Impact (A)* NONE

Weakness Enumeration (CWE)

CWE-ID: CWE-538
CWE Name: CWE-538 Insertion of Sensitive Information into Externally-Accessible File or Directory
Source: BVRP Software

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID: CAPEC-95
CAPEC Description: CAPEC-95 WSDL Scanning


Source: NVD (National Vulnerability Database).