An issue was discovered in CentralSquare Click2Gov Building Permit before October 2023. Lack of access control protections allows remote attackers to arbitrarily delete the contractors from any user's account when the user ID and contractor information is known.
References
Link | Resource |
---|---|
https://github.com/ally-petitt/CVE-2023-40362 | Exploit Third Party Advisory |
https://www.classaction.org/news/centralsquare-hit-with-class-action-over-2017-2018-click2gov-data-breach | Press/Media Coverage Vendor Advisory |
https://github.com/ally-petitt/CVE-2023-40362 | Exploit Third Party Advisory |
https://www.classaction.org/news/centralsquare-hit-with-class-action-over-2017-2018-click2gov-data-breach | Press/Media Coverage Vendor Advisory |
Configurations
History
21 Nov 2024, 08:19
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/ally-petitt/CVE-2023-40362 - Exploit, Third Party Advisory | |
References | () https://www.classaction.org/news/centralsquare-hit-with-class-action-over-2017-2018-click2gov-data-breach - Press/Media Coverage, Vendor Advisory |
19 Jan 2024, 02:09
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-862 | |
CPE | cpe:2.3:a:centralsquare:click2gov_building_permit:-:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
First Time |
Centralsquare click2gov Building Permit
Centralsquare |
|
References | () https://www.classaction.org/news/centralsquare-hit-with-class-action-over-2017-2018-click2gov-data-breach - Press/Media Coverage, Vendor Advisory | |
References | () https://github.com/ally-petitt/CVE-2023-40362 - Exploit, Third Party Advisory |
12 Jan 2024, 08:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-01-12 08:15
Updated : 2024-11-21 08:19
NVD link : CVE-2023-40362
Mitre link : CVE-2023-40362
CVE.ORG link : CVE-2023-40362
JSON object : View
Products Affected
centralsquare
- click2gov_building_permit
CWE
CWE-862
Missing Authorization