CVE-2024-31845

An issue was discovered in Italtel Embrace 1.6.4. The product does not neutralize or incorrectly neutralizes output that is written to logs. The web application writes logs using a GET query string parameter. This parameter can be modified by an attacker, so that every action he performs is attributed to a different user. This can be exploited without authentication.
Configurations

No configuration.

History

21 Nov 2024, 09:14

Type Values Removed Values Added
References () https://www.gruppotim.it/it/footer/red-team.html - () https://www.gruppotim.it/it/footer/red-team.html -

03 Jul 2024, 01:55

Type Values Removed Values Added
CWE CWE-117
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
Summary
  • (es) Se descubrió un problema en Italtel Embrace 1.6.4. El producto no neutraliza o neutraliza incorrectamente la salida escrita en los registros. La aplicación web escribe registros utilizando un parámetro de cadena de consulta GET. Este parámetro puede ser modificado por un atacante, de modo que cada acción que realice se atribuya a un usuario diferente. Esto se puede explotar sin autenticación.

21 May 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-21 16:15

Updated : 2024-11-21 09:14


NVD link : CVE-2024-31845

Mitre link : CVE-2024-31845

CVE.ORG link : CVE-2024-31845


JSON object : View

Products Affected

No product.

CWE
CWE-117

Improper Output Neutralization for Logs