Vulnerabilities > CVE-2023-31435 - Incorrect Authorization vulnerability in Evasys 8.2/9.0

047910
CVSS 8.1 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
evasys
CWE-863

Summary

Multiple components (such as Onlinetemplate-Verwaltung, Liste aller Teilbereiche, Umfragen anzeigen, and questionnaire previews) in evasys before 8.2 Build 2286 and 9.x before 9.0 Build 2401 allow authenticated attackers to read and write to unauthorized data by accessing functions directly.

Vulnerable Configurations

Part Description Count
Application
Evasys
2

Common Weakness Enumeration (CWE)