# CVE-2023-6483: Improper/missing API authentication in ADiTaaS v5.1

DevFeed: [CVE-2023-6483: Improper/missing API authentication in ADiTaaS v5.1](<https://devfeed.tech/articles/cve-2023-6483-improper-missing-api-authentication-in-aditaas-v5-1-32606.md>)

Original publisher: [Read original article](<https://eaton-works.com/2023/12/18/aditaas-cve-2023-6483/>)

Author: Eaton

Published: 2023-12-18T15:52:29Z

Content type: article

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [API](<https://devfeed.tech/topics/api.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Hacking](<https://devfeed.tech/topics/hacking.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [Angular](<https://devfeed.tech/topics/angular.md>), [.NET](<https://devfeed.tech/topics/net.md>)

Tags: [angular](<https://devfeed.tech/tags/angular.md>), [api](<https://devfeed.tech/tags/api.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [backend](<https://devfeed.tech/tags/backend.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [digital](<https://devfeed.tech/tags/digital.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [on-prem](<https://devfeed.tech/tags/on-prem.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

## AI overview

This article examines CVE-2023-6483, a critical API authentication flaw in ADiTaaS v5.1, now Digital Desk. The vulnerability allowed system administrator access by using an administrator user ID in the URL. The article describes responsible disclosure, remediation completed by December 1, 2023, and the range of organizations that could have been affected.

## Source excerpt

The story of CVE-2023-6483, my first CVE and biggest security disclosure yet.