
🚨 CVE-2023-37287: http://SmartBPM.NET - Use of Hard-Coded... Hard-coded auth keys in business process management software = instant domain takeover for any script kiddie with a net... https://zerodaysignal.com/vulnerability/CVE-2023-37287 #netsec #vulnerability #CVE #sysadmin #zeroday
Post summary
A brief notice describes CVE-2023-37287, highlighting hard‑coded authentication keys in SmartBPM.NET that could enable domain takeover, but no PoC, exploit, patch information, or evidence of active exploitation is provided.
