CVE-2023-25780
02.06.2023, 11:15
It is identified a vulnerability of insufficient authentication in an important specific function of Status PowerBPM. A LAN attacker with normal user privilege can exploit this vulnerability to modify substitute agent to arbitrary users, resulting in serious consequence.Enginsight
Vendor | Product | Version |
---|---|---|
status | powerbpm | 2.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration