CVE-2023-45598
A CWE-425 “Direct Request ('Forced Browsing')” vulnerability in the “measure” functionality of the web applicati
A CWE-425 “Direct Request ('Forced Browsing')” vulnerability in the “measure” functionality of the web application allows a remote unauthenticated attacker to access confidential measure information. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.
MEDIUM · CVSS 5.3
EPSS 0.00206
Schedule remediation
- SSVC automatable: yes - attacks can be scripted at scale
Sigma rules0
YARA rules0