CVE-2024-3507

Improper privilege management vulnerability in Lunar software that affects versions 6.0.2 through 6.6.0. This vulnerability allows an attacker to perform a secondary process injection into the Lunar application and abuse those rights to access sensitive user information.
Configurations

No configuration.

History

09 May 2024, 09:15

Type Values Removed Values Added
References
  • {'url': 'https://www.incibe.es/en/incibe-cert/notices/aviso/cross-site-scripting-vulnerability-lunar', 'source': 'cve-coordination@incibe.es'}
  • () https://www.incibe.es/en/incibe-cert/notices/aviso/privilege-escalation-vulnerability-lunar -

08 May 2024, 13:15

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de gestión de privilegios inadecuada en el software Lunar que afecta a las versiones 6.0.2 a 6.6.0. Esta vulnerabilidad permite a un atacante realizar una inyección de proceso secundario en la aplicación Lunar y abusar de esos derechos para acceder a información confidencial del usuario.

08 May 2024, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-08 11:15

Updated : 2024-05-09 09:15


NVD link : CVE-2024-3507

Mitre link : CVE-2024-3507

CVE.ORG link : CVE-2024-3507


JSON object : View

Products Affected

No product.

CWE
CWE-269

Improper Privilege Management