A vulnerability was found in GeoServer GeoWebCache up to 1.15.1. It has been declared as problematic. This vulnerability affects unknown code of the file /geoserver/gwc/rest.html. The manipulation leads to direct request. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-243592.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/Qxyday/GeoServe---unauthorized | Exploit Third Party Advisory | 
| https://vuldb.com/?ctiid.243592 | Permissions Required Third Party Advisory | 
| https://vuldb.com/?id.243592 | Third Party Advisory | 
| https://github.com/Qxyday/GeoServe---unauthorized | Exploit Third Party Advisory | 
| https://vuldb.com/?ctiid.243592 | Permissions Required Third Party Advisory | 
| https://vuldb.com/?id.243592 | Third Party Advisory | 
Configurations
                    History
                    No history.
Information
                Published : 2023-10-26 16:15
Updated : 2024-11-21 08:42
NVD link : CVE-2023-5786
Mitre link : CVE-2023-5786
CVE.ORG link : CVE-2023-5786
JSON object : View
Products Affected
                geoserver
- geowebcache
CWE
                
                    
                        
                        CWE-425
                        
            Direct Request ('Forced Browsing')
