// For flags

CVE-2023-2703

Information Disclosure in Finex Media's Competition Management System

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Finex Media Competition Management System allows Retrieve Embedded Sensitive Data, Collect Data as Provided by Users.This issue affects Competition Management System: before 23.07.

*Credits: Mustafa Anil YILDIRIM
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2023-05-15 CVE Reserved
  • 2023-05-23 CVE Published
  • 2024-08-02 CVE Updated
  • 2024-11-02 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-359: Exposure of Private Personal Information to an Unauthorized Actor
  • CWE-668: Exposure of Resource to Wrong Sphere
CAPEC
  • CAPEC-37: Retrieve Embedded Sensitive Data
  • CAPEC-569: Collect Data as Provided by Users
References (1)
URL Tag Source
https://www.usom.gov.tr/bildirim/tr-23-0283 Government Resource
URL Date SRC
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Finexmedia
Search vendor "Finexmedia"
Competition Management System
Search vendor "Finexmedia" for product "Competition Management System"
< 23.07
Search vendor "Finexmedia" for product "Competition Management System" and version " < 23.07"
-
Affected