CVE-2023-28346
CVSS 3.1 Score 7.3 of 10 (high)
Details
Published May 31, 2023
Updated: Jan 14, 2025
CWE ID 732
Summary
CVE-2023-28346 is a vulnerability affecting Faronics Insight 10.0.19045 on Windows systems. Contrary to the expectation created by Virtual Host Routing, the software unintentionally exposes private API endpoints at /login, /consoleSettings, /console, among others. This exposure allows remote attackers to interact with private pages on the web server, granting them access to privileged actions such as console login and settings modification, if they possess valid credentials.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.