« Volver al listado

CVE-2023-3238

Estado: ModificadaCrítica (9.8)—

A vulnerability, which was classified as critical, has been found in OTCMS up to 6.62. This issue affects some unknown processing of the file /admin/read.php?mudi=getSignal. The manipulation of the argument signalUrl leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-231509 was assigned to this vulnerability.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-3238",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-3238",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-01-02T20:40:02.501241Z"
        }
      }
    ],
    "cvssMetricV2": [
      {
        "type": "Secondary",
        "source": "cna@vuldb.com",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cna@vuldb.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cna@vuldb.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "OTCMS",
          "versions": [
            {
              "status": "affected",
              "version": "6.0"
            },
            {
              "status": "affected",
              "version": "6.1"
            },
            {
              "status": "affected",
              "version": "6.2"
            },
            {
              "status": "affected",
              "version": "6.3"
            },
            {
              "status": "affected",
              "version": "6.4"
            },
            {
              "status": "affected",
              "version": "6.5"
            },
            {
              "status": "affected",
              "version": "6.6"
            },
            {
              "status": "affected",
              "version": "6.7"
            },
            {
              "status": "affected",
              "version": "6.8"
            },
            {
              "status": "affected",
              "version": "6.9"
            },
            {
              "status": "affected",
              "version": "6.10"
            },
            {
              "status": "affected",
              "version": "6.11"
            },
            {
              "status": "affected",
              "version": "6.12"
            },
            {
              "status": "affected",
              "version": "6.13"
            },
            {
              "status": "affected",
              "version": "6.14"
            },
            {
              "status": "affected",
              "version": "6.15"
            },
            {
              "status": "affected",
              "version": "6.16"
            },
            {
              "status": "affected",
              "version": "6.17"
            },
            {
              "status": "affected",
              "version": "6.18"
            },
            {
              "status": "affected",
              "version": "6.19"
            },
            {
              "status": "affected",
              "version": "6.20"
            },
            {
              "status": "affected",
              "version": "6.21"
            },
            {
              "status": "affected",
              "version": "6.22"
            },
            {
              "status": "affected",
              "version": "6.23"
            },
            {
              "status": "affected",
              "version": "6.24"
            },
            {
              "status": "affected",
              "version": "6.25"
            },
            {
              "status": "affected",
              "version": "6.26"
            },
            {
              "status": "affected",
              "version": "6.27"
            },
            {
              "status": "affected",
              "version": "6.28"
            },
            {
              "status": "affected",
              "version": "6.29"
            },
            {
              "status": "affected",
              "version": "6.30"
            },
            {
              "status": "affected",
              "version": "6.31"
            },
            {
              "status": "affected",
              "version": "6.32"
            },
            {
              "status": "affected",
              "version": "6.33"
            },
            {
              "status": "affected",
              "version": "6.34"
            },
            {
              "status": "affected",
              "version": "6.35"
            },
            {
              "status": "affected",
              "version": "6.36"
            },
            {
              "status": "affected",
              "version": "6.37"
            },
            {
              "status": "affected",
              "version": "6.38"
            },
            {
              "status": "affected",
              "version": "6.39"
            },
            {
              "status": "affected",
              "version": "6.40"
            },
            {
              "status": "affected",
              "version": "6.41"
            },
            {
              "status": "affected",
              "version": "6.42"
            },
            {
              "status": "affected",
              "version": "6.43"
            },
            {
              "status": "affected",
              "version": "6.44"
            },
            {
              "status": "affected",
              "version": "6.45"
            },
            {
              "status": "affected",
              "version": "6.46"
            },
            {
              "status": "affected",
              "version": "6.47"
            },
            {
              "status": "affected",
              "version": "6.48"
            },
            {
              "status": "affected",
              "version": "6.49"
            },
            {
              "status": "affected",
              "version": "6.50"
            },
            {
              "status": "affected",
              "version": "6.51"
            },
            {
              "status": "affected",
              "version": "6.52"
            },
            {
              "status": "affected",
              "version": "6.53"
            },
            {
              "status": "affected",
              "version": "6.54"
            },
            {
              "status": "affected",
              "version": "6.55"
            },
            {
              "status": "affected",
              "version": "6.56"
            },
            {
              "status": "affected",
              "version": "6.57"
            },
            {
              "status": "affected",
              "version": "6.58"
            },
            {
              "status": "affected",
              "version": "6.59"
            },
            {
              "status": "affected",
              "version": "6.60"
            },
            {
              "status": "affected",
              "version": "6.61"
            },
            {
              "status": "affected",
              "version": "6.62"
            }
          ]
        }
      ]
    }
  ],
  "published": "2023-06-14T08:15:09.713",
  "references": [
    {
      "url": "https://github.com/HuBenLab/HuBenVulList/blob/main/OTCMS%20is%20vulnerable%20to%20Server-side%20request%20forgery%20(SSRF).md",
      "tags": [
        "Exploit"
      ],
      "source": "cna@vuldb.com"
    },
    {
      "url": "https://vuldb.com/?ctiid.231509",
      "tags": [
        "Permissions Required",
        "Third Party Advisory"
      ],
      "source": "cna@vuldb.com"
    },
    {
      "url": "https://vuldb.com/?id.231509",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cna@vuldb.com"
    },
    {
      "url": "https://github.com/HuBenLab/HuBenVulList/blob/main/OTCMS%20is%20vulnerable%20to%20Server-side%20request%20forgery%20(SSRF).md",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://vuldb.com/?ctiid.231509",
      "tags": [
        "Permissions Required",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://vuldb.com/?id.231509",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cna@vuldb.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-918"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability, which was classified as critical, has been found in OTCMS up to 6.62. This issue affects some unknown processing of the file /admin/read.php?mudi=getSignal. The manipulation of the argument signalUrl leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-231509 was assigned to this vulnerability."
    },
    {
      "lang": "es",
      "value": "Se ha encontrado una vulnerabilidad, clasificada como crítica, en OTCMS hasta la versión 6.62. Este problema afecta a algún procesamiento desconocido del archivo \"/admin/read.php?mudi=getSignal\". La manipulación del argumento \"signalUrl\" conduce a la falsificación de peticiones del lado del servidor. El ataque puede iniciarse de forma remota. El exploit ha sido revelado al público y puede ser utilizado. Se ha asignado el identificador VDB-231509 a esta vulnerabilidad. "
    }
  ],
  "lastModified": "2026-06-17T06:13:38.957",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:otcms:otcms:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D15D5B62-76C4-47E8-8039-402DDCC3E233",
              "versionEndIncluding": "6.62"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cna@vuldb.com"
}