Insecure Permissions Vulnerability in SolarView Compact by SolarView
CVE-2023-29919
Key Information:
- Vendor
Contec
- Vendor
- CVE Published:
- 23 May 2023
Badges
What is CVE-2023-29919?
The SolarView Compact software version 6.0 and earlier has a vulnerability that arises from insufficient permission restrictions on the texteditor.php file. This flaw allows unauthorized users to read or modify any file on the server, potentially leading to data breaches or unauthorized alterations. Proper security measures and permission configurations are essential to mitigate this vulnerability and protect sensitive data.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
60% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability Reserved
