CVE-2024-8601

This vulnerability exists in TechExcel Back Office Software versions prior to 1.0.0 due to improper access controls on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter through API request URL which could lead to unauthorized access to sensitive information belonging to other users.
Configurations

Configuration 1 (hide)

cpe:2.3:a:techexcel:back_office_software:*:*:*:*:*:*:*:*

History

17 Sep 2024, 17:54

Type Values Removed Values Added
CPE cpe:2.3:a:techexcel:back_office_software:*:*:*:*:*:*:*:*
First Time Techexcel back Office Software
Techexcel
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-863
References () https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0285 - () https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0285 - Third Party Advisory

09 Sep 2024, 13:03

Type Values Removed Values Added
Summary
  • (es) Esta vulnerabilidad existe en TechExcel Back Office Software anteriores a la 1.0.0 debido a controles de acceso inadecuados en determinados endpoints de API. Un atacante remoto autenticado podría aprovechar esta vulnerabilidad manipulando un parámetro a través de la URL de solicitud de API, lo que podría dar lugar a un acceso no autorizado a información confidencial perteneciente a otros usuarios.

09 Sep 2024, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-09 10:15

Updated : 2024-09-17 17:54


NVD link : CVE-2024-8601

Mitre link : CVE-2024-8601

CVE.ORG link : CVE-2024-8601


JSON object : View

Products Affected

techexcel

  • back_office_software
CWE
CWE-863

Incorrect Authorization

CWE-639

Authorization Bypass Through User-Controlled Key