CVE detail
CVE-2023-38257 — CVE-2023-38257
Published 2023-07-18 · Modified 2026-06-17 · Vendor iagona · Product scrutisweb · Source nvd
HIGH
severity
CVSS-derived band
0.0072
EPSS probability
exploitation probability, 30d
50.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Iagona ScrutisWeb versions 2.1.37 and prior are vulnerable to an insecure direct object reference vulnerability that could allow an unauthenticated user to view profile information, including user login names and encrypted passwords.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References