Cleartext Storage of Sensitive Information, Exposure of Sensitive Information Through Data Queries vulnerability in Finrota Netahsilat allows Retrieve Embedded Sensitive Data, Authentication Bypass, IMAP/SMTP Command Injection, Collect Data from Common Resource Locations.
This issue solved in versions 1.21.10, 1.23.01, 1.23.08, 1.23.11 and 1.24.03.
References
| Link | Resource |
|---|---|
| https://www.usom.gov.tr/bildirim/tr-24-1611 | Third Party Advisory |
Configurations
History
14 Oct 2025, 13:15
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) Cleartext Storage of Sensitive Information, Exposure of Sensitive Information Through Data Queries vulnerability in Finrota Netahsilat allows Retrieve Embedded Sensitive Data, Authentication Bypass, IMAP/SMTP Command Injection, Collect Data from Common Resource Locations. This issue solved in versions 1.21.10, 1.23.01, 1.23.08, 1.23.11 and 1.24.03. | |
| CWE |
12 Nov 2024, 19:32
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Finrota finrota
Finrota |
|
| References | () https://www.usom.gov.tr/bildirim/tr-24-1611 - Third Party Advisory | |
| CPE | cpe:2.3:a:finrota:finrota:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| Summary |
|
04 Oct 2024, 12:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-10-04 12:15
Updated : 2025-10-14 13:15
NVD link : CVE-2024-6400
Mitre link : CVE-2024-6400
CVE.ORG link : CVE-2024-6400
JSON object : View
Products Affected
finrota
- finrota
