Skip to content

CVE-2023-38257 | ScrutisWeb

Iagona ScrutisWeb versions 2.1.37 and prior are vulnerable to an insecure direct object reference vulnerability that could allow an unauthenticated user to view profile information, including user login names and encrypted passwords..This CVE has a CVSS3.1 score of 7.5 and a Base Severity of HIGH.

InfoDetails
CVE IDCVE-2023-38257
CVE StatePUBLISHED
BaseScore7.5
BaseSeverityHIGH
VectorStringCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
VersionNA

References for CVE-2023-38257 :
https://www.cisa.gov/news-events/ics-advisories/icsa-23-199-03

Metric TypeMetric Score
AttackVector(AV)NETWORK
AttackComplexity(AC)LOW
PrivilegesRequired(PR)NONE
UserInteraction(UI)NONE
Scope(S)UNCHANGED
Confidentiality(C)HIGH
Availability(A)NONE
Integrity(I)NONE