CVE-2023-31923
HIGHSuprema BioStar 2 <2022 Q4 v2.9.1 - Privilege Escalation
Title source: llmDescription
Suprema BioStar 2 before 2022 Q4, v2.9.1 has Insecure Permissions. A vulnerability in the web application allows an authenticated attacker with "User Operator" privileges to create a highly privileged user account. The vulnerability is caused by missing server-side validation, which can be exploited to gain full administrator privileges on the system.
Scores
CVSS v3
8.8
EPSS
0.0008
EPSS Percentile
24.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-281
Status
published
Products (1)
supremainc/biostar_2
< 2.9.1
Published
May 22, 2023
Tracked Since
Feb 18, 2026