Because of an authentication flaw an attacker would be capable of generating a web report that discloses sensitive information such as internal IP addresses, usernames, store names and other sensitive information.
Workaround:
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://csirt.divd.nl/CVE-2023-25913 | third party advisory |
https://csirt.divd.nl/DIVD-2023-00025 | third party advisory |