Description
 An improper authorization level has been detected in the login panel. It may lead to
unauthenticated Server Side Request Forgery and allows to perform open services
enumeration. Server makes query to provided server (Server IP/DNS field) and is
triggering connection to arbitrary address.

Published: 2024-05-07
Score: 5.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-59421  An improper authorization level has been detected in the login panel. It may lead to unauthenticated Server Side Request Forgery and allows to perform open services enumeration. Server makes query to provided server (Server IP/DNS field) and is triggering connection to arbitrary address.
History

No history.

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: OpenText

Published:

Updated: 2024-08-02T08:57:35.206Z

Reserved: 2024-01-23T18:47:50.140Z

Link: CVE-2023-7240

cve-icon Vulnrichment

Updated: 2024-08-02T08:57:35.206Z

cve-icon NVD

Status : Deferred

Published: 2024-05-07T13:15:47.973

Modified: 2026-04-15T00:35:42.020

Link: CVE-2023-7240

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses