CVE-2023-47316

MEDIUM

H-mdm Headwind Mdm - IDOR

Title source: rule
STIX 2.1

Description

Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control. The Web panel allows users to gain access to potentially sensitive API calls such as listing users and their data, file management API calls and audit-related API calls.

References (1)

Core 1
Core References
Exploit, Third Party Advisory
https://boltonshield.com/en/cve/cve-2023-47316/

Scores

CVSS v3 5.4
EPSS 0.0006
EPSS Percentile 19.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-639
Status published
Products (1)
h-mdm/headwind_mdm 5.22.1
Published Nov 22, 2023
Tracked Since Feb 18, 2026