Vulnerabilities > CVE-2023-45393 - Authorization Bypass Through User-Controlled Key vulnerability in Grandingteco Utime Master 9.0.7

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
grandingteco
CWE-639

Summary

An indirect object reference (IDOR) in GRANDING UTime Master v9.0.7-Build:Apr 4,2023 allows authenticated attackers to access sensitive information via a crafted cookie.

Vulnerable Configurations

Part Description Count
Application
Grandingteco
1