An issue was discovered in CentralSquare Click2Gov Building Permit before October 2023. Lack of access control protections allows remote attackers to arbitrarily delete the contractors from any user's account when the user ID and contractor information is known.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2024-01-12T00:00:00

Updated: 2024-01-12T07:55:06.557559

Reserved: 2023-08-14T00:00:00


Link: CVE-2023-40362

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2024-01-12T08:15:43.467

Modified: 2024-01-19T02:09:45.820


Link: CVE-2023-40362

JSON object: View

cve-icon Redhat Information

No data.

CWE