Vulnerability Description
SmartStar Software CWS is a web-based integration platform, it has a vulnerability of missing authorization and users are able to access data or perform actions that they should not be allowed to perform via commands. An authenticated with normal user privilege can execute administrator privilege, resulting in performing arbitrary system operations or disrupting service.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Csharp | Cws Collaborative Development Platform | 10.25 |
Related Weaknesses (CWE)
References
- https://www.twcert.org.tw/tw/cp-132-7594-dac20-1.htmlThird Party Advisory
- https://www.twcert.org.tw/tw/cp-132-7594-dac20-1.htmlThird Party Advisory
FAQ
What is CVE-2023-48375?
CVE-2023-48375 is a vulnerability with a CVSS score of 8.8 (HIGH). SmartStar Software CWS is a web-based integration platform, it has a vulnerability of missing authorization and users are able to access data or perform actions that they should not be allowed to perf...
How severe is CVE-2023-48375?
CVE-2023-48375 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-48375?
Check the references section above for vendor advisories and patch information. Affected products include: Csharp Cws Collaborative Development Platform.