CVE-2023-37287

SmartBPM.NET has a vulnerability of using hard-coded authentication key. An unauthenticated remote attacker can exploit this vulnerability to access system with regular user privilege to read application data, and execute submission and approval processes.
References
Link Resource
https://www.twcert.org.tw/tw/cp-132-7222-cdfd0-1.html Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:smartsoft:smartbpm.net:6.70:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-07-10 02:15

Updated : 2023-07-13 18:59


NVD link : CVE-2023-37287

Mitre link : CVE-2023-37287

CVE.ORG link : CVE-2023-37287


JSON object : View

Products Affected

smartsoft

  • smartbpm.net
CWE
CWE-798

Use of Hard-coded Credentials