Логотип exploitDog
bind:CVE-2024-28735
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-28735

Количество 2

Количество 2

nvd логотип

CVE-2024-28735

почти 2 года назад

Unit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows an authenticated user to modify the password of any user of the application via a crafted request.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2647-rch5-5qg9

почти 2 года назад

An incorrect access control issue in Unit4 Financials by Coda v.2023Q4 allows a remote attacker to escalate privileges via a crafted script to the change password function.

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-28735

Unit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows an authenticated user to modify the password of any user of the application via a crafted request.

CVSS3: 8.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-2647-rch5-5qg9

An incorrect access control issue in Unit4 Financials by Coda v.2023Q4 allows a remote attacker to escalate privileges via a crafted script to the change password function.

CVSS3: 8.1
0%
Низкий
почти 2 года назад

Уязвимостей на страницу