CVE-2023-45892

HIGH

Floorsight Insights Q3 2023 - Info Disclosure

Title source: llm
STIX 2.1

Description

An issue discovered in the Order and Invoice pages in Floorsight Insights Q3 2023 allows an unauthenticated remote attacker to view sensitive customer information.

Scores

CVSS v3 7.5
EPSS 0.0101
EPSS Percentile 77.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (1)
floorsightsoftware/insight < q3_2023
Published Jan 02, 2024
Tracked Since Feb 18, 2026