Show plain JSON{"id": "CVE-2024-28143", "cveTags": [], "metrics": {"cvssMetricV31": [{"type": "Secondary", "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 8.4, "attackVector": "LOCAL", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 2.5}]}, "published": "2024-12-12T14:15:22.173", "references": [{"url": "https://r.sec-consult.com/imageaccess", "source": "551230f0-3615-47bd-b7cc-93e92e730bbf"}, {"url": "https://www.imageaccess.de/?page=SupportPortal&lang=en", "source": "551230f0-3615-47bd-b7cc-93e92e730bbf"}], "vulnStatus": "Awaiting Analysis", "weaknesses": [{"type": "Secondary", "source": "551230f0-3615-47bd-b7cc-93e92e730bbf", "description": [{"lang": "en", "value": "CWE-620"}]}], "descriptions": [{"lang": "en", "value": "The password change function at /cgi/admin.cgi does not require the current/old password, which makes the application vulnerable to account takeover. An attacker can use this to forcefully set a new password within the -rsetpass+-aaction+- parameter\u00a0for a user without knowing the old password, e.g. by exploiting a CSRF issue."}, {"lang": "es", "value": "La funci\u00f3n de cambio de contrase\u00f1a en /cgi/admin.cgi no requiere la contrase\u00f1a actual o anterior, lo que hace que la aplicaci\u00f3n sea vulnerable a la apropiaci\u00f3n de cuentas. Un atacante puede usar esto para configurar a la fuerza una nueva contrase\u00f1a dentro del par\u00e1metro -rsetpass+-aaction+- para un usuario sin conocer la contrase\u00f1a anterior, por ejemplo, explotando un problema CSRF."}], "lastModified": "2024-12-13T16:15:23.590", "sourceIdentifier": "551230f0-3615-47bd-b7cc-93e92e730bbf"}