CVE-2024-12123

A hidden field manipulation vulnerability was identified in Issuetrak version 17.1 that could be triggered by an authenticated user.  When an authenticated user submits a ticket, the request can be intercepted and subsequently modified by using a proxy.  The ticket requester can be changed from the original requester to another user in the same application, which the application then accepts.
CVSS

No CVSS.

Configurations

No configuration.

History

04 Dec 2024, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-04 04:15

Updated : 2024-12-04 04:15


NVD link : CVE-2024-12123

Mitre link : CVE-2024-12123

CVE.ORG link : CVE-2024-12123


JSON object : View

Products Affected

No product.

CWE
CWE-472

External Control of Assumed-Immutable Web Parameter

CWE-837

Improper Enforcement of a Single, Unique Action