Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2023-41508 — CVE-2023-41508 - A hard-coded password in Super Store Finder v3.6 allows attackers to access the administration panel. | Kitploit
Tools/GitHubGitHub/redblueteam/cve-2023-41508
Privilege EscalationVulnerability AnalysisExploitationWeb Application ExploitationAuthenticationMisconfiguration
GitHubredblueteam/cve-2023-41508

CVE-2023-41508

CVE-2023-41508 - A hard-coded password in Super Store Finder v3.6 allows attackers to access the administration panel.

View Repository
123 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2023-41508

CVE-2023-41508 - A hard-coded password in Super Store Finder v3.6 allows attackers to access the administration panel.

Vulnerability Type

Incorrect Access Control

Vendor of Product

Super Store Finder

Affected Product Code Base

Super Store Finder - Affected version 3.6 or below. Fixed in version 3.7

CVSS v3.1 Vector (Base Score)

AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H (10.0)

Affected Component

Affected Web admin console

Attack Type

Remote

Impact Denial of Service

true

Impact Escalation of Privileges

true

Impact Code execution

true

Attack Vectors

The default admin password (admin/password) is hardcoded, defeating the authentication's purpose. Besides, the default admin username and password could not be changed.

Screenshot of the hardcoded password (admin/password) Screenshot of the indicator of error-based SQL injection

Screenshot of the Proof-of-Concept to inject stored cross-site scripting (XSS) due to the absence of input validation for the admin panel Screenshot of the Proof-of-Concept to extract the users table using SQLMap

Screenshot of the Proof-of-Concept to trigger stored cross-site scripting (XSS) Screenshot of the Proof-of-Concept to extract the users table using SQLMap

Patch Notes

https://superstorefinder.net/support/forums/topic/super-store-finder-patch-notes/

Download Tool