CVE-2023-3654

cashIT! - serving solutions. Devices from "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH" to 03.A06rks 2023.02.37 are affected by a origin bypass via the host header in an HTTP request. This vulnerability can be triggered by an HTTP endpoint exposed to the network.
References
Link Resource
https://doi.org/10.35011/ww2q-d522 Technical Description
https://www.cashit.at/ Product
https://doi.org/10.35011/ww2q-d522 Technical Description
https://www.cashit.at/ Product
Configurations

Configuration 1 (hide)

cpe:2.3:a:cashit:cashit\!:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:17

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 9.4
References () https://doi.org/10.35011/ww2q-d522 - Technical Description () https://doi.org/10.35011/ww2q-d522 - Technical Description
References () https://www.cashit.at/ - Product () https://www.cashit.at/ - Product

28 Dec 2023, 15:20

Type Values Removed Values Added
References (MISC) https://doi.org/10.35011/ww2q-d522 - (MISC) https://doi.org/10.35011/ww2q-d522 - Technical Description

02 Nov 2023, 10:15

Type Values Removed Values Added
References
  • (MISC) https://doi.org/10.35011/ww2q-d522 -

04 Oct 2023, 17:42

Type Values Removed Values Added
References (MISC) https://www.cashit.at/ - (MISC) https://www.cashit.at/ - Product
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Cashit cashit\!
Cashit
CWE CWE-346
CPE cpe:2.3:a:cashit:cashit\!:*:*:*:*:*:*:*:*

03 Oct 2023, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-03 09:15

Updated : 2024-11-21 08:17


NVD link : CVE-2023-3654

Mitre link : CVE-2023-3654

CVE.ORG link : CVE-2023-3654


JSON object : View

Products Affected

cashit

  • cashit\!
CWE
CWE-346

Origin Validation Error