Multiple components (such as Onlinetemplate-Verwaltung, Liste aller Teilbereiche, Umfragen anzeigen, and questionnaire previews) in evasys before 8.2 Build 2286 and 9.x before 9.0 Build 2401 allow authenticated attackers to read and write to unauthorized data by accessing functions directly.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://cves.at/posts/cve-2023-31435/writeup/ |
|
History
Thu, 30 Jan 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published: 2023-05-02T00:00:00.000Z
Updated: 2025-01-30T15:09:27.045Z
Reserved: 2023-04-28T00:00:00.000Z
Link: CVE-2023-31435
Updated: 2024-08-02T14:53:30.668Z
Status : Modified
Published: 2023-05-02T20:15:11.187
Modified: 2025-01-30T15:15:15.260
Link: CVE-2023-31435
No data.