CVE-2024-48955

Broken access control in NetAdmin 4.030319 returns data with functionalities on the endpoint that "assembles" the functionalities menus, the return of this call is not encrypted and as the system does not validate the session authorization, an attacker can copy the content of the browser of a user with greater privileges having access to the functionalities of the user that the code was copied.
Configurations

No configuration.

History

31 Oct 2024, 20:15

Type Values Removed Values Added
Summary (en) In NetAdmin 4.0.30319, an attacker can steal a valid session cookie and inject it into another device, granting unauthorized access. This type of attack is commonly referred to as session hijacking. (en) Broken access control in NetAdmin 4.030319 returns data with functionalities on the endpoint that "assembles" the functionalities menus, the return of this call is not encrypted and as the system does not validate the session authorization, an attacker can copy the content of the browser of a user with greater privileges having access to the functionalities of the user that the code was copied.

30 Oct 2024, 15:35

Type Values Removed Values Added
CWE CWE-384
Summary
  • (es) En NetAdmin 4.0.30319, un atacante puede robar una cookie de sesión válida e inyectarla en otro dispositivo, lo que le otorga acceso no autorizado. Este tipo de ataque se conoce comúnmente como secuestro de sesión.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1

29 Oct 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-29 18:15

Updated : 2024-11-01 12:57


NVD link : CVE-2024-48955

Mitre link : CVE-2024-48955

CVE.ORG link : CVE-2024-48955


JSON object : View

Products Affected

No product.

CWE
CWE-384

Session Fixation