Vulnerability Description
Iagona ScrutisWeb versions 2.1.37 and prior are vulnerable to an insecure direct object reference vulnerability that could allow an unauthenticated user to view profile information, including user login names and encrypted passwords.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Iagona | Scrutisweb | <= 2.1.37 |
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-199-03Third Party AdvisoryUS Government Resource
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-199-03Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2023-38257?
CVE-2023-38257 is a vulnerability with a CVSS score of 7.5 (HIGH). Iagona ScrutisWeb versions 2.1.37 and prior are vulnerable to an insecure direct object reference vulnerability that could allow an unauthenticated user to view profile information, including user log...
How severe is CVE-2023-38257?
CVE-2023-38257 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-38257?
Check the references section above for vendor advisories and patch information. Affected products include: Iagona Scrutisweb.