Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to Incorrect Access Control. The `redirect_if_not_loggedin` function in `functions_security.php` fails to terminate script execution after redirecting unauthenticated users. This flaw allows an unauthenticated attacker to upload arbitrary files, potentially leading to Remote Code Execution.
References
Configurations
No configuration.
History
29 Oct 2024, 17:35
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-863 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
25 Oct 2024, 12:56
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
24 Oct 2024, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-10-24 22:15
Updated : 2024-10-29 17:35
NVD link : CVE-2024-41617
Mitre link : CVE-2024-41617
CVE.ORG link : CVE-2024-41617
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization