Dradis through 4.16.0 allows referencing external images (resources) over HTTPS, instead of forcing the use of embedded (uploaded) images. This can be leveraged by an authorized author to attempt to steal the Net-NTLM hashes of other authors on a Windows domain network.
Metrics
Affected Vendors & Products
References
History
Fri, 11 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Mon, 07 Jul 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sat, 05 Jul 2025 03:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Dradis through 4.16.0 allows referencing external images (resources) over HTTPS, instead of forcing the use of embedded (uploaded) images. This can be leveraged by an authorized author to attempt to steal the Net-NTLM hashes of other authors on a Windows domain network. | |
Weaknesses | CWE-294 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-07-05T00:00:00.000Z
Updated: 2025-07-07T18:35:07.867Z
Reserved: 2023-12-14T00:00:00.000Z
Link: CVE-2023-50786

Updated: 2025-07-07T18:33:43.141Z

Status : Awaiting Analysis
Published: 2025-07-05T04:15:24.373
Modified: 2025-07-08T16:18:53.607
Link: CVE-2023-50786

No data.