Unit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows an authenticated user to modify the password of any user of the application via a crafted request.
References
Link | Resource |
---|---|
http://financials.com | Broken Link |
http://unit4.com | Product |
https://packetstormsecurity.com/files/177620/Financials-By-Coda-Authorization-Bypass.html | Exploit Third Party Advisory |
https://www.unit4.com/ | Product |
https://www.unit4.com/products/financial-management-software | Product |
http://financials.com | Broken Link |
http://unit4.com | Product |
https://packetstormsecurity.com/files/177620/Financials-By-Coda-Authorization-Bypass.html | Exploit Third Party Advisory |
https://www.unit4.com/ | Product |
https://www.unit4.com/products/financial-management-software | Product |
Configurations
History
17 Jun 2025, 13:25
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:unit4:financials_by_coda:*:*:*:*:*:*:*:* | |
First Time |
Unit4 financials By Coda
Unit4 |
|
References | () http://financials.com - Broken Link | |
References | () http://unit4.com - Product | |
References | () https://packetstormsecurity.com/files/177620/Financials-By-Coda-Authorization-Bypass.html - Exploit, Third Party Advisory | |
References | () https://www.unit4.com/ - Product | |
References | () https://www.unit4.com/products/financial-management-software - Product |
21 Nov 2024, 09:06
Type | Values Removed | Values Added |
---|---|---|
References | () http://financials.com - | |
References | () http://unit4.com - | |
References | () https://packetstormsecurity.com/files/177620/Financials-By-Coda-Authorization-Bypass.html - | |
References | () https://www.unit4.com/ - | |
References | () https://www.unit4.com/products/financial-management-software - |
01 Aug 2024, 13:49
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.1 |
CWE | CWE-287 |
25 Apr 2024, 19:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Summary |
|
01 Apr 2024, 21:15
Type | Values Removed | Values Added |
---|---|---|
Summary | (en) Unit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows an authenticated user to modify the password of any user of the application via a crafted request. |
20 Mar 2024, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-20 15:15
Updated : 2025-06-17 13:25
NVD link : CVE-2024-28735
Mitre link : CVE-2024-28735
CVE.ORG link : CVE-2024-28735
JSON object : View
Products Affected
unit4
- financials_by_coda
CWE
CWE-287
Improper Authentication