CVE-2024-45789

Sept. 11, 2024, 4:26 p.m.

Undergoing Analysis
CVE has been recently published to the CVE List and has been received by the NVD.

Products

Reedos aiM-Star

  • 2.0.1

Source

vdisclose@cert-in.org.in

Tags

CVE-2024-45789 details

Published : Sept. 11, 2024, 12:15 p.m.
Last Modified : Sept. 11, 2024, 4:26 p.m.

Description

This vulnerability exists in Reedos aiM-Star version 2.0.1 due to improper validation of the ‘mode’ parameter in the API endpoint used during the registration process. An authenticated remote attacker could exploit this vulnerability by manipulating parameter in the API request body on the vulnerable application. Successful exploitation of this vulnerability could allow the attacker to bypass certain constraints in the registration process leading to creation of multiple accounts.

CVSS Score

1 2 3 4 5 6 7 8 9 10

Weakness

Weakness Name Description
CWE-354 Improper Validation of Integrity Check Value The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.
This website uses the NVD API, but is not approved or certified by it.