Логотип exploitDog
bind:CVE-2024-51559
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-51559

Количество 2

Количество 2

nvd логотип

CVE-2024-51559

больше 1 года назад

This vulnerability exists in the Wave 2.0 due to improper authorization checks on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating API input parameters to gain unauthorized access and perform malicious activities on other user accounts.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-hjhx-mr4r-6j6j

больше 1 года назад

This vulnerability exists in the Wave 2.0 due to missing authorization check on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter “user_id” through API request URLs which could lead to unauthorized creation, modification and deletion of alerts belonging to other user accounts.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-51559

This vulnerability exists in the Wave 2.0 due to improper authorization checks on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating API input parameters to gain unauthorized access and perform malicious activities on other user accounts.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-hjhx-mr4r-6j6j

This vulnerability exists in the Wave 2.0 due to missing authorization check on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter “user_id” through API request URLs which could lead to unauthorized creation, modification and deletion of alerts belonging to other user accounts.

CVSS3: 6.5
0%
Низкий
больше 1 года назад

Уязвимостей на страницу