Arbitrary Account Creation Vulnerability in Kodbox
CVE-2023-39691
9.8CRITICAL
What is CVE-2023-39691?
A security vulnerability identified in Kodbox version 1.43 permits malicious actors to create Administrator accounts without proper authorization. This flaw arises from improper handling of GET requests, enabling attackers to exploit the application and gain elevated privileges. The implications of this vulnerability include potential unauthorized access to sensitive data, manipulation of user accounts, and further exploitation of the application environment. Users of Kodbox should prioritize monitoring and applying any available patches to mitigate the risks associated with this vulnerability.
