Vulnerability Description
An issue in LTB Self Service Password before v.1.5.4 allows a remote attacker to execute arbitrary code and obtain sensitive information via hijack of the SMS verification code function to arbitrary phone.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ltb-Project | Self Service Password | < 1.5.4 |
Related Weaknesses (CWE)
References
- https://github.com/ltb-project/self-service-password/issues/816Issue Tracking
- https://github.com/piuppi/Proof-of-Concepts/blob/main/ltb-project/README.mdThird Party Advisory
- https://github.com/ltb-project/self-service-password/issues/816Issue Tracking
- https://github.com/piuppi/Proof-of-Concepts/blob/main/ltb-project/README.mdThird Party Advisory
FAQ
What is CVE-2023-49032?
CVE-2023-49032 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue in LTB Self Service Password before v.1.5.4 allows a remote attacker to execute arbitrary code and obtain sensitive information via hijack of the SMS verification code function to arbitrary p...
How severe is CVE-2023-49032?
CVE-2023-49032 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-49032?
Check the references section above for vendor advisories and patch information. Affected products include: Ltb-Project Self Service Password.