go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

SmartStar Software CWS Web-Base - Use of Hard-coded Credentials

TVN ID TVN-202312004
CVE ID CVE-2023-48374
CVSS 6.5 (Medium)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected Products SmartStar Software CWS Web-Base v10.25
Description SmartStar Software CWS is a web-base integration platform, it has a vulnerability of using a hard-coded for a specific account with low privilege. An unauthenticated remote attacker can exploit this vulnerability to run partial processes and obtain partial information, but can't disrupt service or obtain sensitive information.
Solution Update to the latest version.
Credit Kun Xian Lin(DEVCORE)
Public Date 2023-12-15
Top