SmartBPM.NET has a vulnerability of using hard-coded...
Critical severity
Unreviewed
Published
Jul 10, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
Jul 10, 2023
Published to the GitHub Advisory Database
Jul 10, 2023
Last updated
Apr 4, 2024
SmartBPM.NET has a vulnerability of using hard-coded authentication key. An unauthenticated remote attacker can exploit this vulnerability to access system with regular user privilege to read application data, and execute submission and approval processes.
References