First published: Mon Sep 25 2023(Updated: )
An issue in Service Provider Management System v.1.0 allows a remote attacker to gain privileges via the ID parameter in the /php-spms/admin/?page=user/ endpoint.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oretnom23 Service Provider Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-43457 is critical with a severity value of 9.8.
A remote attacker can exploit CVE-2023-43457 by gaining privileges through the ID parameter in the /php-spms/admin/?page=user/ endpoint.
CVE-2023-43457 affects Service Provider Management System v.1.0.
It is recommended to apply the latest patch or update for Service Provider Management System v.1.0 to fix CVE-2023-43457.
You can find more information about CVE-2023-43457 in the following references: [link1], [link2], [link3].