Vulnerabilities > CVE-2023-38257 - Unspecified vulnerability in Iagona Scrutisweb 2.1.37

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
iagona

Summary

Iagona ScrutisWeb versions 2.1.37 and prior are vulnerable to an insecure direct object reference vulnerability that could allow an unauthenticated user to view profile information, including user login names and encrypted passwords.

Vulnerable Configurations

Part Description Count
Application
Iagona
1