Security Advisory

CVE-2023-45228

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-10-26 16:19:41
Last updated 2025-01-16 21:28:09
Assigner icscert
State PUBLISHED

Description

The application suffers from improper access control when editing users. A user with read permissions can manipulate users, passwords, and permissions by sending a single HTTP POST request with modified parameters.