VulnerabilityModified
CVE-2023-42328
An issue in PeppermintLabs Peppermint v.0.2.4 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the hardcoded session cookie.
HIGH 8.8EPSS 1.16%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.16%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue in PeppermintLabs Peppermint v.0.2.4 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the hardcoded session cookie.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.16% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-798
- Affected
- peppermint/peppermint
- Source
- cve@mitre.org
References
- https://blockomat2100.github.io/posts/2023-09-04-damn-vulnerable-ticket-system/Exploit, Third Party Advisory
- https://github.com/Peppermint-Lab/peppermint/blob/446a20b870bc68157eaafcb7275c289d76bfb29e/apps/client/pages/api/auth/%5B...nextauth%5D.js#L65Issue Tracking
- https://peppermint.sh/Product
- https://blockomat2100.github.io/posts/2023-09-04-damn-vulnerable-ticket-system/Exploit, Third Party Advisory
- https://github.com/Peppermint-Lab/peppermint/blob/446a20b870bc68157eaafcb7275c289d76bfb29e/apps/client/pages/api/auth/%5B...nextauth%5D.js#L65Issue Tracking
- https://peppermint.sh/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.