CVE-2023-4972
CRITICALCVSS 9.8/10EPSS 0.57%
Last modified
CVE-2023-4972 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Incorrect Use of Privileged APIs vulnerability in Yepas Digital Yepas allows Collect Data as Provided by Users. This issue affects Digital Yepas: before 1.0.1.. EPSS estimates a 0.57% chance of exploitation in the next 30 days.
Description
Incorrect Use of Privileged APIs vulnerability in Yepas Digital Yepas allows Collect Data as Provided by Users. This issue affects Digital Yepas: before 1.0.1.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Yepas | Digital Yepas | < 1.0.1 |
References
- https://www.usom.gov.tr/bildirim/tr-23-0526Third Party Advisory
- https://www.usom.gov.tr/bildirim/tr-23-0526Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-4972?
Incorrect Use of Privileged APIs vulnerability in Yepas Digital Yepas allows Collect Data as Provided by Users.
This issue affects Digital Yepas: before 1.0.1.
How severe is CVE-2023-4972?
CVE-2023-4972 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 0.57% probability of exploitation in the next 30 days.
How do I fix CVE-2023-4972?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-4971The Weaver Xtreme Theme Support WordPress plugin before 6.3.…7.2
- CVE-2023-49710Rejected reason: This is unused.
- CVE-2023-49712Rejected reason: This is unused.
- CVE-2023-49713Denial-of-service (DoS) vulnerability exists in NetBIOS serv…7.5
- CVE-2023-49715A unrestricted php file upload vulnerability exists in the i…8.8
- CVE-2023-49716 In Emerson Rosemount GC370XA, GC700XA, and GC1500XA product…9.8
- CVE-2023-49721An insecure default to allow UEFI Shell in EDK2 was left ena…6.7
- CVE-2023-49722Network port 8899 open in WiFi firmware of BCC101/BCC102/BCC…6.5
- CVE-2023-4973A vulnerability was found in Academy LMS 6.2 on Windows. It …6.1
- CVE-2023-49733Improper Restriction of XML External Entity Reference vulner…9.8
- CVE-2023-49734An authenticated Gamma user has the ability to create a dash…6.5
- CVE-2023-49735** UNSUPPORTED WHEN ASSIGNED ** The value set as the Defaul…7.5
Are you affected by CVE-2023-4972?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
