CRITICAL

CVE-2023-3643

CVSS v3

9.8

CRITICAL

EPSS Score

10.1%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This affects an unknown part of the file boss/servlet/document. The manipulation of the argument path leads to file inclusion. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-233889 was assigned to this vulnerability.

Technical details

Published
7/12/2023
Exploit-DB
EDB-52482

Frequently asked questions

What is CVE-2023-3643?

A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This affects an unknown part of the file boss/servlet/document. The manipulation of the argument path leads to file inclusion. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-233889 was assigned to this vulnerability.

Is CVE-2023-3643 actively exploited?

Active exploitation of CVE-2023-3643 has not been confirmed. The EPSS score is 10.1%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2023-3643?

CVE-2023-3643 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2023-3643 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.