CVE-2023-46906: Medium severity juzaweb cms vulnerability
Published Jan 9, 2024
·Updated
juzaweb <= 3.4 is vulnerable to Incorrect Access Control, resulting in an application outage after a 500 HTTP status code. The payload in the timezone field was not correctly validated.
Affected Software
2 affected components
juzaweb CMS<=3.4
composer/juzaweb/cms<=3.4
Event History
Jan 9, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·03:30 AM
Data Sourced
via GitHub·03:30 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-46906?
CVE-2023-46906 has a severity rating that indicates it poses a significant risk due to incorrect access control and potential application outages.
2
How do I fix CVE-2023-46906?
To fix CVE-2023-46906, ensure that the timezone field is properly validated and implement stricter access control measures.
3
What software versions are affected by CVE-2023-46906?
CVE-2023-46906 affects Juzaweb CMS versions up to and including 3.4.
4
What is the impact of CVE-2023-46906?
The impact of CVE-2023-46906 can result in application outages triggered by unvalidated inputs leading to HTTP 500 errors.
5
Is CVE-2023-46906 publicly disclosed?
Yes, CVE-2023-46906 has been publicly disclosed and documented for awareness and mitigation.