CVE-2023-50872
The API in Accredible Credential.net December 6th, 2023 allows an Insecure Direct Object Reference attack that discloses partial information about certificates and their respective holder. NOTE: the excellium-services.com web page about this issue mentions "Vendor says that it's not a security issue."
Published:Apr 16, 2024
Last Modified:Apr 15, 2026
EPS:Apr 16, 2024
EPSS Score:0.00284
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Accredible Credential.net
Product
Accredible Credential.net
Accredible Credential.net
Accredible Credential.net
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
