CVE-2023-7240
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
07/05/2024
Last modified:
07/05/2024
Description
An improper authorization level has been detected in the login panel. It may lead to<br />
unauthenticated Server Side Request Forgery and allows to perform open services<br />
enumeration. Server makes query to provided server (Server IP/DNS field) and is<br />
triggering connection to arbitrary address.<br />
<br />
Impact
Base Score 3.x
5.80
Severity 3.x
MEDIUM



