Vulnerability record · CVE-2023-5830 · published 27 October 2023
CVE-2023-5830: ColumbiaSoft Document Locator WebTools login improper authentication
Documentlocator · Document Locator
CVE-2023-5830 is a critical improper authentication flaw (CWE-287) in ColumbiaSoft Document Locator's WebTools component, specifically the /api/authentication/login endpoint. Manipulating the Server argument allows an attacker to bypass authentication. The vendor addressed it in version 7.2 SP4 and 2021.1.
Description
A vulnerability classified as critical has been found in ColumbiaSoft Document Locator. This affects an unknown part of the file /api/authentication/login of the component WebTools. The manipulation of the argument Server leads to improper authentication. It is possible to initiate the attack remotely. Upgrading to version 7.2 SP4 and 2021.1 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-243729 was assigned to this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, and a high EPSS score (0.60782) indicate severe risk and likely active exploitation.
What it is
CVE-2023-5830 is a critical improper authentication flaw (CWE-287) in ColumbiaSoft Document Locator's WebTools component, specifically the /api/authentication/login endpoint. Manipulating the Server argument allows an attacker to bypass authentication. The vendor addressed it in version 7.2 SP4 and 2021.1.
Impact
An unauthenticated remote attacker can bypass authentication on the login API, potentially gaining access to the application with the privileges of the impersonated or default account. Given the CVSS vector (C:H/I:H/A:H), full compromise of confidentiality, integrity, and availability is possible.
Attack surface
Reachable over the network via the /api/authentication/login endpoint of the WebTools component; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Not listed in CISA KEV and no public exploit references are provided; EPSS probability is 0.60782 (99.1st percentile), indicating a high likelihood of exploitation activity in the wild.
What to do
- Upgrade Document Locator to version 7.2 SP4 or 2021.1 as recommended by the vendor.
- If immediate upgrade is not possible, restrict network access to the /api/authentication/login endpoint to trusted networks or IP ranges.
- Monitor and log authentication attempts to the WebTools API for anomalous Server argument values.
- Apply network segmentation to limit exposure of the WebTools component to the internet.
Detection
- Inspect web server and application logs for requests to /api/authentication/login with unusual or unexpected Server parameter values.
- Alert on successful authentication events originating from untrusted or unexpected source IPs.
- Correlate multiple failed login attempts followed by a successful login from the same source within a short window.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://vuldb.com/?ctiid.243729 | Permissions Required |
| https://vuldb.com/?id.243729 | Third Party Advisory |
| https://vuldb.com/?ctiid.243729 | Permissions Required |
| https://vuldb.com/?id.243729 | Third Party Advisory |
Track CVE-2023-5830 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-5830), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.