CVE-2023-49233

Insufficient access checks in Visual Planning Admin Center 8 before v.1 Build 240207 allow attackers in possession of a non-administrative Visual Planning account to utilize functions normally reserved for administrators. The affected functions allow attackers to obtain different types of configured credentials and potentially elevate their privileges to administrator level.
Configurations

No configuration.

History

24 Oct 2024, 20:35

Type Values Removed Values Added
CWE CWE-284 CWE-522
Summary
  • (es) Los controles de acceso insuficientes en Visual Planning Admin Center 8 antes de la versión 1, compilación 240207 permiten que los atacantes que poseen una cuenta de Visual Planning no administrativa utilicen funciones que normalmente están reservadas para los administradores. Las funciones afectadas permiten a los atacantes obtener distintos tipos de credenciales configuradas y potencialmente elevar sus privilegios al nivel de administrador.

03 Sep 2024, 21:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CWE CWE-284

03 Sep 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-03 17:15

Updated : 2024-10-24 20:35


NVD link : CVE-2023-49233

Mitre link : CVE-2023-49233

CVE.ORG link : CVE-2023-49233


JSON object : View

Products Affected

No product.

CWE
CWE-522

Insufficiently Protected Credentials