Логотип exploitDog
bind:CVE-2024-51556
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-51556

Количество 2

Количество 2

nvd логотип

CVE-2024-51556

больше 1 года назад

This vulnerability exists in the Wave 2.0 due to insufficient encryption of sensitive data received at the API response. An authenticated remote attacker could exploit this vulnerability by manipulating API input parameters through API request URL/payload leading to unauthorized access to sensitive information belonging to other users.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-6w35-x982-hj9h

больше 1 года назад

This vulnerability exists in the Wave 2.0 due to weak encryption of sensitive data received at the API response. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter “user_id” through API request URLs leading to unauthorized access to sensitive information belonging to other users.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-51556

This vulnerability exists in the Wave 2.0 due to insufficient encryption of sensitive data received at the API response. An authenticated remote attacker could exploit this vulnerability by manipulating API input parameters through API request URL/payload leading to unauthorized access to sensitive information belonging to other users.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-6w35-x982-hj9h

This vulnerability exists in the Wave 2.0 due to weak encryption of sensitive data received at the API response. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter “user_id” through API request URLs leading to unauthorized access to sensitive information belonging to other users.

CVSS3: 6.5
0%
Низкий
больше 1 года назад

Уязвимостей на страницу