CVE-2024-51556

This vulnerability exists in the Wave 2.0 due to insufficient encryption of sensitive data received at the API response. An authenticated remote attacker could exploit this vulnerability by manipulating API input parameters through API request URL/payload leading to unauthorized access to sensitive information belonging to other users.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:63moons:aero:*:*:*:*:*:*:*:*
cpe:2.3:a:63moons:wave_2.0:*:*:*:*:*:*:*:*

History

22 Nov 2024, 12:15

Type Values Removed Values Added
Summary (en) This vulnerability exists in the Wave 2.0 due to weak encryption of sensitive data received at the API response. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter “user_id” through API request URLs leading to unauthorized access to sensitive information belonging to other users. (en) This vulnerability exists in the Wave 2.0 due to insufficient encryption of sensitive data received at the API response. An authenticated remote attacker could exploit this vulnerability by manipulating API input parameters through API request URL/payload leading to unauthorized access to sensitive information belonging to other users.

08 Nov 2024, 15:20

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
First Time 63moons wave 2.0
63moons
63moons aero
Summary
  • (es) Esta vulnerabilidad existe en Wave 2.0 debido a un cifrado débil de los datos confidenciales recibidos en la respuesta de la API. Un atacante remoto autenticado podría aprovechar esta vulnerabilidad manipulando un parámetro “user_id” a través de las URL de solicitud de la API, lo que daría lugar a un acceso no autorizado a información confidencial perteneciente a otros usuarios.
References () https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0332 - () https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0332 - Third Party Advisory
CPE cpe:2.3:a:63moons:wave_2.0:*:*:*:*:*:*:*:*
cpe:2.3:a:63moons:aero:*:*:*:*:*:*:*:*

04 Nov 2024, 13:17

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-04 13:17

Updated : 2024-11-22 12:15


NVD link : CVE-2024-51556

Mitre link : CVE-2024-51556

CVE.ORG link : CVE-2024-51556


JSON object : View

Products Affected

63moons

  • aero
  • wave_2.0
CWE
CWE-327

Use of a Broken or Risky Cryptographic Algorithm