CVE-2024-47085

This vulnerability exists in Apex Softcell LD DP Back Office due to improper validation of certain parameters (cCdslClicentcode and cLdClientCode) in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating parameters in the API request body leading to exposure of sensitive information belonging to other users.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apexsoftcell:ld_geo:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:apexsoftcell:ld_dp_back_office:*:*:*:*:*:*:*:*

History

26 Sep 2024, 15:30

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
References () https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0296 - () https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0296 - Third Party Advisory
CPE cpe:2.3:a:apexsoftcell:ld_dp_back_office:*:*:*:*:*:*:*:*
cpe:2.3:a:apexsoftcell:ld_geo:*:*:*:*:*:*:*:*
First Time Apexsoftcell ld Geo
Apexsoftcell ld Dp Back Office
Apexsoftcell
CWE NVD-CWE-Other

20 Sep 2024, 13:15

Type Values Removed Values Added
Summary (en) This vulnerability exists in Apex Softcell LD DP Back Office due to improper validation of certain parameters “cCdslClicentcode” and “cLdClientCode” in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating parameters in the API request body leading to exposure of sensitive information belonging to other users. (en) This vulnerability exists in Apex Softcell LD DP Back Office due to improper validation of certain parameters (cCdslClicentcode and cLdClientCode) in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating parameters in the API request body leading to exposure of sensitive information belonging to other users.

20 Sep 2024, 12:30

Type Values Removed Values Added
Summary
  • (es) Esta vulnerabilidad existe en Apex Softcell LD DP Back Office debido a la validación incorrecta de ciertos parámetros “cCdslClicentcode” y “cLdClientCode” en el endpoint de la API. Un atacante remoto autenticado podría aprovechar esta vulnerabilidad manipulando los parámetros en el cuerpo de la solicitud de la API, lo que provocaría la exposición de información confidencial perteneciente a otros usuarios.

19 Sep 2024, 07:15

Type Values Removed Values Added
Summary (en) This vulnerability exists in LD DP Back Office due to improper validation of certain parameters “cCdslClicentcode” and “cLdClientCode” in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating parameters in the API request body leading to exposure of sensitive information belonging to other users. (en) This vulnerability exists in Apex Softcell LD DP Back Office due to improper validation of certain parameters “cCdslClicentcode” and “cLdClientCode” in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating parameters in the API request body leading to exposure of sensitive information belonging to other users.

19 Sep 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-19 06:15

Updated : 2024-09-26 15:30


NVD link : CVE-2024-47085

Mitre link : CVE-2024-47085

CVE.ORG link : CVE-2024-47085


JSON object : View

Products Affected

apexsoftcell

  • ld_dp_back_office
  • ld_geo
CWE
NVD-CWE-Other CWE-359

Exposure of Private Personal Information to an Unauthorized Actor