Read Time:24 Second
Posted by Clément Cruchet on Apr 10
CVE ID: CVE-2023-27195
Description:
An access control issue in Trimble TM4Web v22.2.0 allows
unauthenticated attackers to access a specific crafted URL path to
retrieve the last registration access code and use this access code to
register a valid account. If the access code was used to create an
Administrator account, attackers are also able to register new
Administrator accounts with full rights and privileges.
Vulnerability Type: Broken…