This vulnerability exists in Shilpi Client Dashboard due to improper handling of multiple parameters in the API endpoint. An authenticated remote attacker could exploit this vulnerability by including multiple “userid” parameters in the API request body leading to unauthorized access of sensitive information belonging to other users.
References
Link | Resource |
---|---|
https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0313 | Third Party Advisory |
Configurations
History
10 Oct 2024, 21:01
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:shilpi:client_dashboard:*:*:*:*:*:*:*:* | |
First Time |
Shilpi client Dashboard
Shilpi |
|
References | () https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0313 - Third Party Advisory | |
Summary |
|
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
CWE | NVD-CWE-Other |
04 Oct 2024, 12:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-10-04 12:15
Updated : 2024-10-10 21:01
NVD link : CVE-2024-47651
Mitre link : CVE-2024-47651
CVE.ORG link : CVE-2024-47651
JSON object : View
Products Affected
shilpi
- client_dashboard
CWE