CVE-2024-44860

An information disclosure vulnerability in the /Letter/PrintQr/ endpoint of Solvait v24.4.2 allows attackers to access sensitive data via a crafted request.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:solvait:solvait:24.4.2:*:*:*:*:*:*:*

History

10 Jul 2025, 15:38

Type Values Removed Values Added
References () https://gist.github.com/walhajri/e03974097d1fd4eb698a6a80931bdd45 - () https://gist.github.com/walhajri/e03974097d1fd4eb698a6a80931bdd45 - Exploit, Third Party Advisory
References () https://www.solvait.com/ - () https://www.solvait.com/ - Product
CPE cpe:2.3:a:solvait:solvait:24.4.2:*:*:*:*:*:*:*
First Time Solvait solvait
Solvait

30 Sep 2024, 12:46

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de divulgación de información en el endpoint /Letter/PrintQr/ de Solvait v24.4.2 permite a los atacantes acceder a datos confidenciales a través de una solicitud manipulada específicamente para ello.

26 Sep 2024, 18:35

Type Values Removed Values Added
CWE CWE-284
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

26 Sep 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-26 17:15

Updated : 2025-07-10 15:38


NVD link : CVE-2024-44860

Mitre link : CVE-2024-44860

CVE.ORG link : CVE-2024-44860


JSON object : View

Products Affected

solvait

  • solvait
CWE
CWE-284

Improper Access Control