NA

CVE-2023-40362

Published: 12/01/2024 Updated: 19/01/2024
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

An issue exists in CentralSquare Click2Gov Building Permit before October 2023. Lack of access control protections allows remote malicious users to arbitrarily delete the contractors from any user's account when the user ID and contractor information is known.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

centralsquare click2gov building permit -

Github Repositories

CVE-2023-40362 Vulnerabilitiy details and proof of concept

CVE-2023-40362 CVE-2023-40362 vulnerabilitiy details and proof-of-concept Overview An access control vulnerability in Click2Gov BP at the URI /Click2GovBP/mastercontractorlisthtml leads to the ability for authenticated users to delete the contractors from the accounts of other users with the victim's user ID and the information of the contractor to delete This is caused