CVE-2024-47657

Oct. 4, 2024, 1:50 p.m.

Awaiting Analysis
CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.

Products

Shilpi Net Back Office

Source

vdisclose@cert-in.org.in

Tags

CVE-2024-47657 details

Published : Oct. 4, 2024, 1:15 p.m.
Last Modified : Oct. 4, 2024, 1:50 p.m.

Description

This vulnerability exists in the Shilpi Net Back Office due to improper access controls on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter dfclientid through API request URLs which could lead to unauthorized access to sensitive information belonging to other users.

CVSS Score

1 2 3 4 5 6 7 8 9 10

Weakness

Weakness Name Description
CWE-639 Authorization Bypass Through User-Controlled Key The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
This website uses the NVD API, but is not approved or certified by it.