Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2023-46501 — BoltWire v6.03 vulnerable to "Improper Access Control" | Kitploit
Tools/GitHubGitHub/cyber-wo0dy/cve-2023-46501
Vulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringPenetration Testing
GitHubcyber-wo0dy/cve-2023-46501

CVE-2023-46501

BoltWire v6.03 vulnerable to "Improper Access Control"

View Repository
142 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2023-46501 - BoltWire v6.03 - Improper Access Control

Description

In version 6.03 of BoltWire CMS, it is possible to exploit an “Improper Access Control” vulnerability, through the index.php?p=member.admin&action=data parameter, allowing an attacker to view any member's password, including the from the admin, thus allowing the theft of information, arbitrary changes to data or manipulation of the application for malicious purposes.

To Fix

Update to the latest version of BoltWire CMS.

Steps to Reproduce:

1) Create a new member. step 1

2) Access the following URL: http://domain.com/folder/index.php?p=member.admin&action=data

Note: replace http://domain.com/folder/ with the address of the application to be tested.

3) As a result, you will be able to view the admin password. step 3

Download Tool

4) To view other users' passwords, simply change the “admin” parameter in the URL provided above to another user's name, for example member.user.