CVE-2023-3643
moderate-risk
Published 2023-07-12
A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This affects an unknown part of the file boss/servlet/document. The manipulation of the argument path leads to file inclusion. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-233889 was assigned to this vulnerability.
Do I need to act?
!
41.3% chance of exploitation in next 30 days
EPSS score — higher than 59% of all CVEs
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
!
1 public exploit available
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.3/10
High
NETWORK
/ LOW complexity
Affected Products (1)
Affected Vendors
References (6)
Third Party Advisory
https://vuldb.com/?ctiid.233889
Third Party Advisory
https://vuldb.com/?id.233889
Third Party Advisory
https://vuldb.com/?ctiid.233889
Third Party Advisory
https://vuldb.com/?id.233889
48
/ 100
moderate-risk
Severity
26/34 · High
Exploitability
17/34 · Moderate
Exposure
5/34 · Minimal