Multiple components (such as Onlinetemplate-Verwaltung, Liste aller Teilbereiche, Umfragen anzeigen, and questionnaire previews) in evasys before 8.2 Build 2286 and 9.x before 9.0 Build 2401 allow authenticated attackers to read and write to unauthorized data by accessing functions directly.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://cves.at/posts/cve-2023-31435/writeup/ |
![]() ![]() |
History
Thu, 30 Jan 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: mitre
Published: 2023-05-02T00:00:00.000Z
Updated: 2025-01-30T15:09:27.045Z
Reserved: 2023-04-28T00:00:00.000Z
Link: CVE-2023-31435

Updated: 2024-08-02T14:53:30.668Z

Status : Modified
Published: 2023-05-02T20:15:11.187
Modified: 2025-01-30T15:15:15.260
Link: CVE-2023-31435

No data.