Dradis through 4.16.0 allows referencing external images (resources) over HTTPS, instead of forcing the use of embedded (uploaded) images. This can be leveraged by an authorized author to attempt to steal the Net-NTLM hashes of other authors on a Windows domain network.
Metrics
Affected Vendors & Products
References
History
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 07 Jul 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 05 Jul 2025 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dradis through 4.16.0 allows referencing external images (resources) over HTTPS, instead of forcing the use of embedded (uploaded) images. This can be leveraged by an authorized author to attempt to steal the Net-NTLM hashes of other authors on a Windows domain network. | |
| Weaknesses | CWE-294 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-07-05T00:00:00.000Z
Updated: 2025-07-07T18:35:07.867Z
Reserved: 2023-12-14T00:00:00.000Z
Link: CVE-2023-50786
Updated: 2025-07-07T18:33:43.141Z
Status : Awaiting Analysis
Published: 2025-07-05T04:15:24.373
Modified: 2025-07-08T16:18:53.607
Link: CVE-2023-50786
No data.