vendor:
Answer
by:
Eduardo Pérez-Malumbres Cervera
9.8
CVSS
CRITICAL
Account Takeover
284
CWE
Product Name: Answer
Affected Version From: 1.0.3
Affected Version To: 1.0.3
Patch Exists: NO
Related CWE: CVE-2023-0744
CPE: answerdev
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=59563, https://www.infosecmatter.com/nessus-plugin-library/?id=59570, https://www.infosecmatter.com/nessus-plugin-library/?id=68807, https://www.infosecmatter.com/nessus-plugin-library/?id=68545, https://www.infosecmatter.com/nessus-plugin-library/?id=147213, https://www.infosecmatter.com/nessus-plugin-library/?id=63445, https://www.infosecmatter.com/nessus-plugin-library/?id=68708, https://www.infosecmatter.com/nessus-plugin-library/?id=25081, https://www.infosecmatter.com/nessus-plugin-library/?id=63544, https://www.infosecmatter.com/nessus-plugin-library/?id=63552
Platforms Tested: Ubuntu 22.04 / Debian 11
2023
Answerdev 1.0.3 – Account Takeover
Answerdev 1.0.3 is vulnerable to an account takeover vulnerability. An attacker can exploit this vulnerability by sending a malicious request to the application's API endpoint to reset the password of a user. This will allow the attacker to gain access to the user's account.
Mitigation:
The application should implement proper authentication and authorization mechanisms to prevent unauthorized access to the application's API endpoints.