CVE-2023-48249 Information
Jan 11, 2024
cve
Description
The vulnerability allows an authenticated remote attacker to list arbitrary folders in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request.
By abusing this vulnerability it is possible to steal session cookies of other active users.
Reference
https://psirt.bosch.com/security-advisories/BOSCH-SA-711465.html
Share on: