CVE-2023-28698

CRITICAL

Wade Graphic Design FANTSY - Privilege Escalation

Title source: llm
STIX 2.1

Description

Wade Graphic Design FANTSY has a vulnerability of insufficient authorization check. An unauthenticated remote user can exploit this vulnerability by modifying URL parameters to gain administrator privileges to perform arbitrary system operation or disrupt service.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0085
EPSS Percentile 53.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-863
Status published
Products (1)
wddgroup/fantsy 2.1.8
Published Jun 02, 2023
Tracked Since Feb 18, 2026