CVE-2023-48374

MEDIUM

SmartStar Software CWS - Use of Hard-coded Credentials

Title source: llm
STIX 2.1

Description

SmartStar Software CWS is a web-base integration platform, it has a vulnerability of using a hard-coded for a specific account with low privilege. An unauthenticated remote attacker can exploit this vulnerability to run partial processes and obtain partial information, but can't disrupt service or obtain sensitive information.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0055
EPSS Percentile 41.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-798
Status published
Products (1)
csharp/cws_collaborative_development_platform 10.25
Published Dec 15, 2023
Tracked Since Feb 18, 2026