CVE-2024-40530

A vulnerability in Pantera CRM versions 401.152 and 402.072 allows unauthorized attackers to bypass IP-based access controls by manipulating the X-Forwarded-For header.
Configurations

No configuration.

History

28 Aug 2024, 19:15

Type Values Removed Values Added
Summary (en) Insecure Permissions vulnerability in UAB Lexita PanteraCRM CMS v.401.152 and Patera CRM CMS v.402.072 allows a remote attacker to execute arbitrary code via modification of the X-Forwarded-For header component. (en) A vulnerability in Pantera CRM versions 401.152 and 402.072 allows unauthorized attackers to bypass IP-based access controls by manipulating the X-Forwarded-For header.

06 Aug 2024, 15:35

Type Values Removed Values Added
CWE CWE-94
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
Summary
  • (es) Vulnerabilidad de permisos inseguros en UAB Lexita PanteraCRM CMS v.401.152 y Patera CRM CMS v.402.072 permite a un atacante remoto ejecutar código arbitrario mediante la modificación del componente de encabezado X-Forwarded-For.

05 Aug 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-05 16:15

Updated : 2024-08-28 19:15


NVD link : CVE-2024-40530

Mitre link : CVE-2024-40530

CVE.ORG link : CVE-2024-40530


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')