|04 October 2023
|All below 188.8.131.52940
|Vulnerability type (CWE)
|Missing Authorization (CWE-862)
|Report to CERT Polska
CERT Polska has received a report about vulnerability in UptimeDC software and participated in its coordination. The vulnerability allows every logged in user to change administrator password, subsequently leading to a privilege escalation. The weakness has been confirmed by the vendor and assigned the number CVE-2023-4997. The vulnerability was fixed in version 184.108.40.206940, all below are vulnerable.
We thank Antoni Kwietniewski from Alior Bank for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.