Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-55519 | Dradis through 4.16.0 allows referencing external images (resources) over HTTPS, instead of forcing the use of embedded (uploaded) images. This can be leveraged by an authorized author to attempt to steal the Net-NTLM hashes of other authors on a Windows domain network. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 07 Nov 2025 10:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:dradisframework:dradis:*:*:*:*:community:*:*:* |
Fri, 11 Jul 2025 22:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 08 Jul 2025 04:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 05 Jul 2025 12:30:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dradis through 4.16.0 allows referencing external images (resources) over HTTPS, instead of forcing the use of embedded (uploaded) images. This can be leveraged by an authorized author to attempt to steal the Net-NTLM hashes of other authors on a Windows domain network. | |
| Weaknesses | CWE-294 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-07-07T18:35:07.867Z
Reserved: 2023-12-14T00:00:00.000Z
Link: CVE-2023-50786
Updated: 2025-07-07T18:33:43.141Z
Status : Analyzed
Published: 2025-07-05T04:15:24.373
Modified: 2025-11-07T01:11:54.913
Link: CVE-2023-50786
No data.
OpenCVE Enrichment
Updated: 2025-07-14T06:48:00Z
EUVD