CVE-2023-5635

CVSS 3.1 Score 7.5 of 10 (high)

Attack Complexity low
Confidentiality high
Integrity none
Availability none
Scope unchanged
Privileges Required none

Details

Published Dec 1, 2023
Updated: Dec 6, 2023
CWE ID 1320

Summary

CVE-2023-5635 is an Improper Protection for Outbound Error Messages and Alert Signals vulnerability discovered in ArslanSoft Education Portal. This issue enables account footprinting, allowing unauthorized entities to gather sensitive information about user accounts in the affected Education Portal versions before v1.1. This vulnerability can potentially lead to security breaches and unauthorized access to educational data. The inadequate protection of error messages and alert signals allows attackers to obtain valuable information, compromising the security and confidentiality of user data. It is crucial for organizations using ArslanSoft Education Portal to upgrade to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share