go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Ai3 QbiBot - Broken Access Control

TVN ID TVN-202404004
CVE ID CVE-2024-3777
CVSS 9.8 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products QbiBot v8.0.4 and earlier version
Description The password reset feature of Ai3 QbiBot lacks proper access control, allowing unauthenticated remote attackers to reset any user's password.
Solution Update to v8.0.5 or latter version, or contact vendor for remediation
Credit Huding(DEVCORE)
Public Date 2024-04-15
Top