CVE-2023-43194 describes an Incorrect Access Control vulnerability in Submitty versions prior to v22.06.00, allowing an unauthenticated attacker to delete any forum post by manipulating request parameters. This medium-severity vulnerability (CVSS 5.3) has a low attack complexity and can lead to data integrity compromise (deletion of posts). There is currently no evidence of active exploitation, and no public exploit code or Metasploit modules are available, though it has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
22.06.00CPE matchmatch criteria | cpe:2.3:a:rcos:submitty:22.06.00:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.