CVE-2023-53740
CRITICALScreen SFT DAB Series 1.9.3 - Unauthenticated Authentication Bypass via userManager.cgx Endpoint
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-53740. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit bypasses authentication by directly changing the admin password via an API call without requiring the old password. It sends a crafted JSON payload to the target endpoint to modify the admin credentials.
Description
Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without providing the current credentials. Attackers can exploit the userManager.cgx endpoint by sending a crafted JSON request with a new MD5-hashed password to directly modify the admin account.
Exploits (1)
This exploit bypasses authentication by directly changing the admin password via an API call without requiring the old password. It sends a crafted JSON payload to the target endpoint to modify the admin credentials.
References (6)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H