Missing Authentication for Critical Function in BP Social Connect - CVE-2023-2704

 

Missing Authentication for Critical Function in BP Social Connect - CVE-2023-2704

Published: June 14, 2024


Vulnerability identifier: #VU92117
CSH Severity: High
CVSS v4 BT: 8.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber]
CVE-ID: CVE-2023-2704
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass security restrictions on the target system.

The vulnerability exists due to insufficient verification on the user being supplied during a Facebook login through the plugin. A remote unauthenticated attacker can bypass security restrictions on the target system and log in as any existing user on the site, such as an administrator.


Affected software

BP Social Connect
Storage Resource Manager
Dell EMC Storage Monitoring and Reporting (SMR)

How to mitigate CVE-2023-2704

Install updates from vendor's website.

BP Social Connect - update to 1.6.2
Storage Resource Manager - update to 4.10.0.3
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.10.0.3

External References

Related Security Bulletins