CVE-2024-57490

Guangzhou Hongfan Technology Co., LTD. iOffice20 has any user login vulnerability. An attacker can log in to any system account including the system administrator through a logical flaw.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ioffice:ioffice20:-:*:*:*:*:*:*:*

History

01 Apr 2025, 20:23

Type Values Removed Values Added
CPE cpe:2.3:a:ioffice:ioffice20:-:*:*:*:*:*:*:*
Summary
  • (es) iOffice20 de Guangzhou Hongfan Technology Co., LTD. presenta una vulnerabilidad de inicio de sesión. Un atacante puede iniciar sesión en cualquier cuenta del sistema, incluyendo la del administrador, mediante una falla lógica.
First Time Ioffice ioffice20
Ioffice
References () https://gist.github.com/NaliangzzZ/44bfcc1d9c2cf275d2b6683ca9e20980 - () https://gist.github.com/NaliangzzZ/44bfcc1d9c2cf275d2b6683ca9e20980 - Third Party Advisory
References () https://www.ioffice.cn - () https://www.ioffice.cn - Product

24 Mar 2025, 18:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.7
CWE CWE-287

21 Mar 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-21 14:15

Updated : 2025-04-01 20:23


NVD link : CVE-2024-57490

Mitre link : CVE-2024-57490

CVE.ORG link : CVE-2024-57490


JSON object : View

Products Affected

ioffice

  • ioffice20
CWE
CWE-287

Improper Authentication