CVE-2023-37362

Weintek Weincloud v0.13.6 could allow an attacker to abuse the registration functionality to login with testing credentials to the official website.
References
Link Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-23-199-04 Third Party Advisory US Government Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-23-199-04 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

cpe:2.3:a:weintek:weincloud:0.13.6:*:*:*:*:*:*:*

History

06 Mar 2025, 15:15

Type Values Removed Values Added
Summary (en) Weintek Weincloud v0.13.6 could allow an attacker to abuse the registration functionality to login with testing credentials to the official website. (en) Weintek Weincloud v0.13.6 could allow an attacker to abuse the registration functionality to login with testing credentials to the official website.
CWE CWE-287 CWE-522

21 Nov 2024, 08:11

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 8.8
v2 : unknown
v3 : 7.2
References () https://www.cisa.gov/news-events/ics-advisories/icsa-23-199-04 - Third Party Advisory, US Government Resource () https://www.cisa.gov/news-events/ics-advisories/icsa-23-199-04 - Third Party Advisory, US Government Resource

26 Jul 2023, 16:18

Type Values Removed Values Added
References (MISC) https://www.cisa.gov/news-events/ics-advisories/icsa-23-199-04 - (MISC) https://www.cisa.gov/news-events/ics-advisories/icsa-23-199-04 - Third Party Advisory, US Government Resource
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CPE cpe:2.3:a:weintek:weincloud:0.13.6:*:*:*:*:*:*:*

19 Jul 2023, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-07-19 22:15

Updated : 2025-03-06 15:15


NVD link : CVE-2023-37362

Mitre link : CVE-2023-37362

CVE.ORG link : CVE-2023-37362


JSON object : View

Products Affected

weintek

  • weincloud
CWE
CWE-522

Insufficiently Protected Credentials