CVE-2024-47651

This vulnerability exists in Shilpi Client Dashboard due to improper handling of multiple parameters in the API endpoint. An authenticated remote attacker could exploit this vulnerability by including multiple “userid” parameters in the API request body leading to unauthorized access of sensitive information belonging to other users.
Configurations

Configuration 1 (hide)

cpe:2.3:a:shilpi:client_dashboard:*:*:*:*:*:*:*:*

History

10 Oct 2024, 21:01

Type Values Removed Values Added
CPE cpe:2.3:a:shilpi:client_dashboard:*:*:*:*:*:*:*:*
First Time Shilpi client Dashboard
Shilpi
References () https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0313 - () https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0313 - Third Party Advisory
Summary
  • (es) Esta vulnerabilidad existe en Shilpi Client Dashboard debido al manejo inadecuado de múltiples parámetros en el endpoint de la API. Un atacante remoto autenticado podría aprovechar esta vulnerabilidad al incluir múltiples parámetros de “identificación de usuario” en el cuerpo de la solicitud de la API, lo que provocaría un acceso no autorizado a información confidencial perteneciente a otros usuarios.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE NVD-CWE-Other

04 Oct 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-04 12:15

Updated : 2024-10-10 21:01


NVD link : CVE-2024-47651

Mitre link : CVE-2024-47651

CVE.ORG link : CVE-2024-47651


JSON object : View

Products Affected

shilpi

  • client_dashboard
CWE
NVD-CWE-Other CWE-235

Improper Handling of Extra Parameters