CVE-2024-2412

The disabling function of the user registration page for Heimavista Rpage and Epage is not properly implemented, allowing remote attackers to complete user registration on sites where user registration is supposed to be disabled.
Configurations

No configuration.

History

21 Nov 2024, 09:09

Type Values Removed Values Added
References () https://www.twcert.org.tw/tw/cp-132-7696-0951f-1.html - () https://www.twcert.org.tw/tw/cp-132-7696-0951f-1.html -

14 Oct 2024, 07:15

Type Values Removed Values Added
CWE CWE-284 CWE-1220

13 Mar 2024, 12:33

Type Values Removed Values Added
Summary
  • (es) La función de desactivación de la página de registro de usuarios para Heimavista Rpage y Epage no está implementada correctamente, lo que permite a atacantes remotos completar el registro de usuarios en sitios donde se supone que el registro de usuarios está desactivado.

13 Mar 2024, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-13 03:15

Updated : 2024-11-21 09:09


NVD link : CVE-2024-2412

Mitre link : CVE-2024-2412

CVE.ORG link : CVE-2024-2412


JSON object : View

Products Affected

No product.

CWE
CWE-1220

Insufficient Granularity of Access Control