CVE-2023-47315

Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control due to a hard-coded JWT Secret. The secret is hardcoded into the source code available to anyone on Git Hub. This secret is used to sign the application’s JWT token and verify the incoming user-supplied tokens.
References
Link Resource
https://boltonshield.com/en/cve/cve-2023-47315/ Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:h-mdm:headwind_mdm:5.22.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-11-22 17:15

Updated : 2023-11-30 21:15


NVD link : CVE-2023-47315

Mitre link : CVE-2023-47315

CVE.ORG link : CVE-2023-47315


JSON object : View

Products Affected

h-mdm

  • headwind_mdm
CWE
CWE-798

Use of Hard-coded Credentials