Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-37454 | In ebankIT 6, the public endpoints /public/token/Email/generate and /public/token/SMS/generate allow generation of OTP messages to any e-mail address or phone number without validation. (It cannot be exploited with e-mail addresses or phone numbers that are registered in the application.) |
Tue, 14 Jan 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-01-14T18:11:35.155Z
Reserved: 2023-05-22T00:00:00.000Z
Link: CVE-2023-33291
Updated: 2024-08-02T15:39:35.996Z
Status : Modified
Published: 2023-05-28T22:15:09.453
Modified: 2025-01-14T19:15:30.877
Link: CVE-2023-33291
No data.
OpenCVE Enrichment
No data.
EUVD