CVE-2023-49706
CVSS 3.1 Score 6.8 of 10 (medium)
Details
Published Dec 19, 2023
Updated: Dec 28, 2023
CWE ID 362
Summary
CVE-2023-49706 is a vulnerability affecting LinOTP Self Service in versions 3.x before 3.2.5. This issue arises from a defective request context handling mechanism, which enables unauthenticated attackers to escalate privileges. Attackers can exploit this vulnerability by generating repeated API requests to create a race condition with ongoing user activity in the self-service portal. Consequently, they gain the ability to act as another user with the respective permissions, posing a significant security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share