VulnerabilityModified
CVE-2023-40362
Lack of access control protections allows remote attackers to arbitrarily delete the contractors from any user's account when the user ID and contractor information is known.
MEDIUM 4.3EPSS 0.67%
Does this matter?
Lower severity and a low EPSS score (0.67%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in CentralSquare Click2Gov Building Permit before October 2023. Lack of access control protections allows remote attackers to arbitrarily delete the contractors from any user's account when the user ID and contractor information is known.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.67% probability · 50th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862
- Affected
- centralsquare/click2gov building permit
- Source
- cve@mitre.org
References
- https://github.com/ally-petitt/CVE-2023-40362Exploit, Third Party Advisory
- https://www.classaction.org/news/centralsquare-hit-with-class-action-over-2017-2018-click2gov-data-breachPress/Media Coverage, Vendor Advisory
- https://github.com/ally-petitt/CVE-2023-40362Exploit, Third Party Advisory
- https://www.classaction.org/news/centralsquare-hit-with-class-action-over-2017-2018-click2gov-data-breachPress/Media Coverage, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.