CVE-2023-39691: Critical severity kodcloud vulnerability
Published Jan 16, 2024
·Updated
An issue discovered in kodbox through 1.43 allows attackers to arbitrarily add Administrator accounts via crafted GET request.
Affected Software
1 affected component
Kodcloud Kodbox<=1.43
Event History
Jan 16, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-39691?
CVE-2023-39691 is considered a high severity vulnerability due to its potential for unauthorized administrative access.
2
How do I fix CVE-2023-39691?
To fix CVE-2023-39691, update Kodbox to version 1.44 or later, which addresses this vulnerability.
3
What systems are affected by CVE-2023-39691?
CVE-2023-39691 affects all versions of Kodbox up to and including 1.43.
4
Can CVE-2023-39691 allow remote attacks?
Yes, CVE-2023-39691 can allow remote attackers to gain administrative control through crafted GET requests.
5
What are the implications of CVE-2023-39691?
The implications of CVE-2023-39691 include the potential for attackers to manage and manipulate sensitive data on affected systems.