During testing of the plugin, a vulnerability was discovered that allows the user, starting from the “Subscriber” (lower privs) privileges, to access AJAX requests that can output the following data: password and login from the database -which is very critical, password and login from the mailbox, phpinfo() and all the information that the plugin can output about the web application
CVE-2023-5713 – System Dashboard – Broken Logical Control to Mail Box password Thief – POC
![CVE-2023-5713 – System Dashboard – Broken Logical Control to Mail Box password Thief – POC CVE-2023-5713 – System Dashboard – Broken Logical Control to Mail Box password Thief – POC](https://research.cleantalk.org/wp-content/uploads/2023/10/New_1_not_safe-1.png)