nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-36347 CVE-2023-36347
HIGHNuclei
POS Codekop v2.0 - Broken Authentication
Record summary
CVE-2023-36347 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
A broken authentication mechanism in the endpoint excel.php of POS Codekop v2.0 allows unauthenticated attackers to download selling data.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 27, 2024 · Source: CVE List
Nuclei templates
1ProjectDiscoveryHIGHPOS Codekop v2.0 - Broken AuthenticationCVSS 7.5
A broken authentication mechanism in the endpoint excel.php of POS Codekop v2.0 allows unauthenticated attackers to download selling data.
Impact
Successful exploitation could lead to unauthorized access to sensitive information.
Remediation
Implement proper authentication mechanisms and ensure secure user session management.
WeaknessesCWE-306
Authorsprincechaddha
Template tagscvecve2023codekopposauth-bypassvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:codekop:codekop:2.0:*:*:*:*:*:*:*
Source: ProjectDiscovery
References
3youtube.com
https://www.youtube.com/watch?v=7qaIeE2cyO4 yuyudhn.github.io
https://yuyudhn.github.io/pos-codekop-vulnerability