An issue found in DERICIA Co. Ltd, DELICIA v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp DELICIA function.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Link | Tags |
---|---|
http://delicia.com | product |
http://dericia.com | product |
https://github.com/syz913/CVE-reports/blob/main/CVE-2023-31824.md | third party advisory exploit |