Vulnerability Description
Anonymous user may get the list of existing users managed by the application, that could ease further attacks (see CVE-2023-3065 and 3066)This issue affects Mobatime mobile application AMXGT100 through 1.3.20.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mobatime | Amxgt 100 | <= 1.3.20 |
Related Weaknesses (CWE)
References
- https://borelenzo.github.io/stuff/2023/06/02/cve-2023-3064_65_66.htmlExploitThird Party Advisory
- https://borelenzo.github.io/stuff/2023/06/02/cve-2023-3064_65_66.htmlExploitThird Party Advisory
FAQ
What is CVE-2023-3064?
CVE-2023-3064 is a vulnerability with a CVSS score of 7.5 (HIGH). Anonymous user may get the list of existing users managed by the application, that could ease further attacks (see CVE-2023-3065 and 3066)This issue affects Mobatime mobile application AMXGT100 throug...
How severe is CVE-2023-3064?
CVE-2023-3064 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-3064?
Check the references section above for vendor advisories and patch information. Affected products include: Mobatime Amxgt 100.