CVE-2023-33368

MEDIUM

Control ID IDSecure <4.7.26.0 - Info Disclosure

Title source: llm

Description

Some API routes exists in Control ID IDSecure 4.7.26.0 and prior, exfiltrating sensitive information and passwords to users accessing these API routes.

Scores

CVSS v3 6.5
EPSS 0.0016
EPSS Percentile 36.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-668
Status published

Affected Products (1)

assaabloy/control_id_idsecure < 4.7.26.0

Timeline

Published Aug 03, 2023
Tracked Since Feb 18, 2026