๐Ÿ” CVE Alert

CVE-2023-33291

HIGH 7.4
CVSS Score
7.4
EPSS Score
0.0%
EPSS Percentile
0th

In ebankIT 6, the public endpoints /public/token/Email/generate and /public/token/SMS/generate allow generation of OTP messages to any e-mail address or phone number without validation. (It cannot be exploited with e-mail addresses or phone numbers that are registered in the application.)

Vendor n/a
Product n/a
Published May 28, 2023
Last Updated Jan 14, 2025
Stay Ahead of the Next One

Get instant alerts for n/a n/a

Be the first to know when new high vulnerabilities affecting n/a n/a are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

n/a / n/a
n/a

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
ebankit.com: https://www.ebankit.com/digital-banking-platform packetstormsecurity.com: http://packetstormsecurity.com/files/172476/eBankIT-6-Arbitrary-OTP-Generation.html