CVE-2023-27195 - Trimble TM4Web Auth Bypass and Account Registration

2 weeks ago 7
ARTICLE AD BOX
CVE ID : CVE-2023-27195
Published : Nov. 8, 2024, 5:15 a.m. | 24 minutes ago
Description : Trimble TM4Web 22.2.0 allows unauthenticated attackers to access /inc/tm_ajax.msw?func=UserfromUUID&uuid= to retrieve the last registration access code and use this access code to register a valid account. via a PUT /inc/tm_ajax.msw request. If the access code was used to create an Administrator account, attackers are also able to register new Administrator accounts with full privileges.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Read Entire Article