Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2023-33730 — eScan Management Console version 14.0.1400.2281 contains privilege escalation via `GetUserCurrentPwd` function lets attackers retrieve any user's password in plain text. | Kitploit
Tools/GitHubGitHub/sahiloj/cve-2023-33730
Authentication & AuthorizationPrivilege EscalationReconnaissancePassword AttacksVulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringPenetration TestingPapers & ResearchLearning & Education
11177 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHubsahiloj/cve-2023-33730

CVE-2023-33730

eScan Management Console version 14.0.1400.2281 contains privilege escalation via `GetUserCurrentPwd` function lets attackers retrieve any user's password in plain text.

View Repository

CVE-2023-33730 — eScan Management Console Privilege Escalation

Severity: Critical
CVE ID: CVE-2023-33730
Disclosed: 30 May 2023
Author: Sahil Ojha


Table of Contents

  • Overview
  • Vulnerability Details
  • Impact
  • Technical Analysis
  • Proof of Concept
  • Remediation
  • References
  • Disclaimer

Overview

eScan Management Console is a centralised security management solution developed by Microworld Technologies. It allows enterprise IT administrators to deploy, manage, and monitor eScan antivirus/endpoint-protection agents across an entire network from a single web-based console.

Version 14.0.1400.2281 of this console contains a critical Privilege Escalation vulnerability. Due to a missing authorization check in the GetUserCurrentPwd API endpoint, any authenticated user — regardless of their privilege level — can retrieve the plaintext passwords of every account registered in the console, including administrator accounts. This immediately enables full takeover of the management console and, by extension, all managed endpoints on the network.


Vulnerability Details

FieldValue
CVE IDCVE-2023-33730
ProductMicroworld Technologies eScan Management Console
Vulnerable Version14.0.1400.2281
Vulnerability TypePrivilege Escalation / Broken Object-Level Authorization (BOLA / IDOR)
Attack VectorNetwork (authenticated low-privileged user)
AuthenticationRequired (any valid user account)
CVSS ScoreCritical
Disclosure Date30 May 2023
ResearcherSahil Ojha
Vendor Homepagehttps://www.escanav.com
Affected Softwarehttps://cl.escanav.com/ewconsole.dll
Tested OnWindows

Impact

This vulnerability has a critical real-world impact:

  • Horizontal Privilege Escalation — A normal (low-privileged) user can retrieve the plaintext passwords of all other normal users, enabling account takeover across the same privilege tier.
  • Vertical Privilege Escalation — By manipulating a single URL parameter (UsrId), the same low-privileged user can retrieve the plaintext password of the administrator account, granting full administrative control over the eScan Management Console.
  • Mass Credential Exposure — All user passwords are stored and returned in plaintext, meaning a single API call can enumerate credentials for every account in the system simultaneously.
  • Full Network Compromise — Because the eScan Management Console controls antivirus/endpoint agents across the entire enterprise network, administrative access to the console may allow an attacker to disable endpoint protection, deploy malicious software, or pivot to other systems on the network.

Technical Analysis

The vulnerability resides in the GetUserCurrentPwd function exposed by the eScan Management Console web interface. This endpoint is intended to allow a user to retrieve their own password for profile-editing purposes. However, the implementation suffers from a Broken Object-Level Authorization (BOLA / IDOR) flaw:

  1. No ownership check — The endpoint accepts a UsrId parameter but does not verify that the requesting user owns the account corresponding to that ID.
  2. No privilege check — Any authenticated session, regardless of role, is permitted to invoke this endpoint for any UsrId value.
  3. Plaintext password storage / response — Passwords are returned in plaintext in the HTTP response body, bypassing any encryption or hashing protection that may otherwise exist.

Vulnerable request pattern:

GET /eScanWebConsole/webpages/...?action=GetUserCurrentPwd&UsrId=<TARGET_USER_ID> HTTP/1.1
Host: <escan-console-host>
Cookie: <valid-session-cookie>

By iterating over sequential UsrId values, an attacker can dump the credentials of every user in the system in a single automated sweep.


Proof of Concept

Note: The following steps demonstrate the vulnerability in a controlled lab environment. Do not attempt to reproduce this against any system you do not own or have explicit written permission to test.

Step 1 — Create a low-privileged user

Log in to the eScan Management Console using valid administrator credentials and create a new user account with normal (low) privilege level access.

Step 1 – Create normal user


Step 2 — Log in as the low-privileged user

Log out of the administrator session and log in using the credentials of the newly created normal user.

Step 2 – Log in as normal user


Step 3 — Capture the profile-edit GET request

While logged in as the normal user, navigate to the Edit Profile / Change Password section. Intercept the outgoing HTTP traffic using Burp Suite (or a comparable HTTP proxy). Identify and capture the GetUserCurrentPwd GET request as shown below.

Step 3 – Capture GET request in Burp Suite


Step 4 — Forward the request and observe the plaintext password

Send the captured request to Burp Suite Repeater and forward it. Observe that the server response contains the plaintext password of the currently authenticated normal user — no administrator privileges required to retrieve it.

Step 4 – Plaintext password returned in response


Step 5 — Escalate to administrator by modifying UsrId

In Burp Suite Repeater, modify the UsrId parameter to the ID of the administrator account (or any other account). Forward the modified request. The server responds with the administrator's plaintext password, as well as the passwords of any other user whose UsrId is supplied.

Step 5 – Administrator password exposed via IDOR


Step 6 — Full account takeover

Use the retrieved administrator password to log in to the console as the administrator, gaining full administrative privileges over the eScan Management Console and all managed endpoints on the network.


Remediation

Microworld Technologies should apply the following mitigations:

Download Tool