An improper authorization level has been detected in the login panel. It may lead to
unauthenticated Server Side Request Forgery and allows to perform open services
enumeration. Server makes query to provided server (Server IP/DNS field) and is
triggering connection to arbitrary address.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-59421  An improper authorization level has been detected in the login panel. It may lead to unauthenticated Server Side Request Forgery and allows to perform open services enumeration. Server makes query to provided server (Server IP/DNS field) and is triggering connection to arbitrary address.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: OpenText

Published:

Updated: 2024-08-02T08:57:35.206Z

Reserved: 2024-01-23T18:47:50.140Z

Link: CVE-2023-7240

cve-icon Vulnrichment

Updated: 2024-08-02T08:57:35.206Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-07T13:15:47.973

Modified: 2024-11-21T08:45:35.173

Link: CVE-2023-7240

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses