Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-31845

Опубликовано: 21 мая 2024
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

An issue was discovered in Italtel Embrace 1.6.4. The product does not neutralize or incorrectly neutralizes output that is written to logs. The web application writes logs using a GET query string parameter. This parameter can be modified by an attacker, so that every action he performs is attributed to a different user. This can be exploited without authentication.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:italtel:embrace:1.6.4:*:*:*:*:*:*:*

EPSS

Процентиль: 40%
0.00184
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-117

Связанные уязвимости

CVSS3: 5.3
github
больше 1 года назад

An issue was discovered in Italtel Embrace 1.6.4. The product does not neutralize or incorrectly neutralizes output that is written to logs. The web application writes logs using a GET query string parameter. This parameter can be modified by an attacker, so that every action he performs is attributed to a different user. This can be exploited without authentication.

EPSS

Процентиль: 40%
0.00184
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-117