NA

CVE-2024-23687

Published: 19/01/2024 Updated: 26/01/2024
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Hard-coded credentials in FOLIO mod-data-export-spring versions prior to 1.5.4 and from 2.0.0 to 2.0.2 allows unauthenticated users to access critical APIs, modify user data, modify configurations including single-sign-on, and manipulate fees/fines.

Vulnerable Product Search on Vulmon Subscribe to Product

openlibraryfoundation mod-data-export-spring