CVE-2024-6400

Cleartext Storage of Sensitive Information, Exposure of Sensitive Information Through Data Queries vulnerability in Finrota Netahsilat allows Retrieve Embedded Sensitive Data, Authentication Bypass, IMAP/SMTP Command Injection, Collect Data from Common Resource Locations. This issue solved in versions 1.21.10, 1.23.01, 1.23.08, 1.23.11 and 1.24.03.
References
Link Resource
https://www.usom.gov.tr/bildirim/tr-24-1611 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:finrota:finrota:*:*:*:*:*:*:*:*

History

14 Oct 2025, 13:15

Type Values Removed Values Added
Summary (en) Cleartext Storage of Sensitive Information vulnerability in Finrota Netahsilat allows Retrieve Embedded Sensitive Data.This issue solved in versions 1.21.10, 1.23.01, 1.23.08, 1.23.11 and 1.24.03. (en) Cleartext Storage of Sensitive Information, Exposure of Sensitive Information Through Data Queries vulnerability in Finrota Netahsilat allows Retrieve Embedded Sensitive Data, Authentication Bypass, IMAP/SMTP Command Injection, Collect Data from Common Resource Locations. This issue solved in versions 1.21.10, 1.23.01, 1.23.08, 1.23.11 and 1.24.03.
CWE CWE-311

12 Nov 2024, 19:32

Type Values Removed Values Added
First Time Finrota finrota
Finrota
References () https://www.usom.gov.tr/bildirim/tr-24-1611 - () https://www.usom.gov.tr/bildirim/tr-24-1611 - Third Party Advisory
CPE cpe:2.3:a:finrota:finrota:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
Summary
  • (es) La vulnerabilidad de almacenamiento de información confidencial en texto plano en Finrota Netahsilat permite recuperar datos confidenciales integrados. Este problema se resolvió en las versiones 1.21.10, 1.23.01, 1.23.08, 1.23.11 y 1.24.03.

04 Oct 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-04 12:15

Updated : 2025-10-14 13:15


NVD link : CVE-2024-6400

Mitre link : CVE-2024-6400

CVE.ORG link : CVE-2024-6400


JSON object : View

Products Affected

finrota

  • finrota
CWE
CWE-202

Exposure of Sensitive Information Through Data Queries

CWE-312

Cleartext Storage of Sensitive Information