Record summary

CVE-2023-36347 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

A broken authentication mechanism in the endpoint excel.php of POS Codekop v2.0 allows unauthenticated attackers to download selling data.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 27, 2024 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryHIGHPOS Codekop v2.0 - Broken AuthenticationCVSS 7.5

A broken authentication mechanism in the endpoint excel.php of POS Codekop v2.0 allows unauthenticated attackers to download selling data.

Impact

Successful exploitation could lead to unauthorized access to sensitive information.

Remediation

Implement proper authentication mechanisms and ensure secure user session management.

WeaknessesCWE-306
Authorsprincechaddha
Template tagscvecve2023codekopposauth-bypassvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:codekop:codekop:2.0:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3