Anonymous user may get the list of existing users managed by the application, that could ease further attacks (see CVE-2023-3065 and 3066)This issue affects Mobatime mobile application AMXGT100 through 1.3.20.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
The product stores sensitive information without properly limiting read or write access by unauthorized actors.
Link | Tags |
---|---|
https://borelenzo.github.io/stuff/2023/06/02/cve-2023-3064_65_66.html | third party advisory exploit |