CVE-2023-48865: Medium severity composer/reportico-web/reportico vulnerability
Published Apr 11, 2024
·Updated
An issue discovered in Reportico Till 8.1.0 allows attackers to obtain sensitive information via executemode parameter of the URL.
Affected Software
2 affected components
composer/reportico-web/reportico<=8.1.0
Reportico Reportico=8.1.0
Event History
Apr 11, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
Description
Data Sourced
via NVD·10:15 PM
SeverityWeaknessAffected Software
Apr 12, 2024
Advisory Published
via GitHub·12:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2023-48865?
CVE-2023-48865 is classified as a high-severity vulnerability due to its potential to expose sensitive information.
2
How can I mitigate CVE-2023-48865?
To mitigate CVE-2023-48865, upgrade to Reportico version 8.1.1 or later, where the vulnerability is resolved.
3
Who is affected by CVE-2023-48865?
CVE-2023-48865 affects users of Reportico version 8.1.0.
4
What kind of information can be exposed by CVE-2023-48865?
CVE-2023-48865 may allow attackers to access sensitive information through manipulation of the execute_mode parameter in the URL.
5
Is CVE-2023-48865 a remote attack vector?
Yes, CVE-2023-48865 can be exploited remotely by sending crafted requests to the affected application.