NA

CVE-2023-33730

Published: 31/05/2023 Updated: 08/06/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2281 allows any remote malicious user to retrieve password of any admin or normal user in plain text format.

Vulnerable Product Search on Vulmon Subscribe to Product

escanav escan management console 14.0.1400.2281

Github Repositories

eScan Management Console 14014002281 - Privilege Escalation Description: Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14014002281 allows any remote attacker to retrieve password of any admin or normal user in plain text format resulting in vertical as well as horizontal privilege escalation Vulnera