CVE-2023-5830
ColumbiaSoft Document Locator WebTools login improper authentication
Record summary
CVE-2023-5830 has a selected CVSS score of 7.3 (high); EIP currently links 1 Nuclei template.
Description
A vulnerability classified as critical has been found in ColumbiaSoft Document Locator. This affects an unknown part of the file /api/authentication/login of the component WebTools. The manipulation of the argument Server leads to improper authentication. It is possible to initiate the attack remotely. Upgrading to version 7.2 SP4 and 2021.1 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-243729 was assigned to this vulnerability.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Apr 11, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 9, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Document LocatorBrowse ColumbiaSoft / Document Locator | CVE List | Version range not supplied | affected |
document_locatorBrowse documentlocator / document_locator | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALColumbiaSoft DocumentLocator - Improper AuthenticationCVSS 9.8
Instances of ColumbiaSoft's Document Locator prior to version 7.2 SP4 and 2021.1 are vulnerable to an Improper Authentication/SSRF vulnerability. This template identifies vulnerable instances of the ColumbiaSoft Document Locater application by confirming external DNS interaction/lookups by modifying the value of the client-side SERVER parameter at /api/authentication/login.
Impact
An attacker could exploit this vulnerability to gain unauthorized access to sensitive information.
Remediation
Upgrade to a patched version of ColumbiaSoft DocumentLocator to fix the improper authentication issue.
Source: ProjectDiscovery