CVE-2023-45893: Floorsightsoftware Customer Portal
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
An indirect Object Reference (IDOR) in the Order and Invoice pages in Floorsight Customer Portal Q3 2023 allows an unauthenticated remote attacker to view sensitive customer information.
Affected products
- Floorsightsoftware Customer Portal: up to and including q3_2023
Published 2024-01-02. Last modified 2026-06-17.